Solved

DoS attack

Posted on 2014-03-25
3
452 Views
Last Modified: 2014-04-01
Is it possible to block certain foreign countries altogether to prevent a DoS attack, also what else can be done to prevent a DoS attack on a public facing 3845 Cisco ISR?
0
Comment
Question by:dcawood
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 3

Accepted Solution

by:
englanddg earned 167 total points
ID: 39953299
Not the best answer, but you can set the firewall to ignore entire IP blocks?

Country assigned blocks are here:

http://www.nirsoft.net/countryip/

That being said, you'll still get the traffic, and the firewall will still need to handle it (even if it's just ignoring it...)
0
 
LVL 4

Assisted Solution

by:Pancake_Effect
Pancake_Effect earned 167 total points
ID: 39953333
The ISP can filter the IP range for you, thus diverting the problem before it even reaches you.

On your side however, the best way to manage it is to install a firewall box on the network. You can prevent some common DDOS attacks by blocking certain ports and turning off pings to the device. On a Cisco 5510 for example you can set it up to detect such things as well to help prevent issues. That however won't stop a DDOS attack overall, it will still spend it's resources trying to block it. That's why if it's a active DDOS attack I would call the ISP to block the IP range.
0
 
LVL 25

Assisted Solution

by:Tony Giangreco
Tony Giangreco earned 166 total points
ID: 39953414
I suggest contacting your ISP. normally unless you have an enterprise type account, they won't do much. We use Sonicwall and their Geo-IP filter which allows us to block all foreign countries. You might want to look into a Cisco option that does the same.

You might also try moving to a new IP and putting it into stealth mode with Ping turned off so they can't detect you as easily.

Hope this helps!
0

Featured Post

How to Defend Against the WCry Ransomware Attack

On May 12, 2017, an extremely virulent ransomware variant named WCry 2.0 began to infect organizations. Within several hours, over 75,000 victims were reported in 90+ countries. Learn more from our research team about this threat & how to protect your organization!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This paper addresses the security of Sennheiser DECT Contact Center and Office (CC&O) headsets. It describes the DECT security chain comprised of “Pairing”, “Per Call Authentication” and “Encryption”, which are all part of the standard DECT protocol.
Did you know that more than 4 billion data records have been recorded as lost or stolen since 2013? It was a staggering number brought to our attention during last week’s ManageEngine webinar, where attendees received a comprehensive look at the ma…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question