Solved

RDP Server Land Attack

Posted on 2014-04-07
7
1,816 Views
Last Modified: 2014-04-10
I've been receiving a few of these alert messages every other day for a week. I have a Sonicwall TZ210W firewall.

The firewall has the latest firmware and appears to be working properly.

04/07/2014 13:32:27.880 - Alert - Intrusion Prevention - Land attack dropped -       x.x.x.x, 11, X1 - x.x.x.x, 11 -

Any idea where to start?
0
Comment
Question by:Tony Giangreco
  • 4
  • 3
7 Comments
 
LVL 8

Accepted Solution

by:
Lee Ingalls earned 500 total points
ID: 39984107
I have the same Sonicwall TZ210...

A dropped event is a service that is denied entry into the SonicWALL because it
violates configured or default security policies. No response is returned to the sender of the  event.

"Land Attack Dropped - The SonciWALL has detected and blocked SYN packets whose
source IP addresses are spoofed to be the same as the destination IP addresses".

Review:
Firewall Service Objects
Security Services - Intrusion Prevention - IPS Policies

Are you doing VoIP?
0
 
LVL 25

Author Comment

by:Tony Giangreco
ID: 39984120
So if this starts happening constantly, I'd assume we are having a Doss attack. if not, it's just something to ignore since we don't have an origination IP. Correct?
0
 
LVL 8

Expert Comment

by:Lee Ingalls
ID: 39984139
It's dropping the event without response to the originating sender. I'd say monitor and report to your Service Provider should it persist... since you'd prefer not to have that traffic at all.

I was having similar for a period of time and said something to my provider near contract renewal time and haven't seen them since.

Are you using RDP or Terminal Services through your firewall?
0
NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

 
LVL 25

Author Comment

by:Tony Giangreco
ID: 39984150
Yes, we have five servers. 3-DC, 1 Exchange and 1 RDP/Terminal Server
0
 
LVL 8

Expert Comment

by:Lee Ingalls
ID: 39984185
Make sure it's not a mis-configured or unstable RDP/TS client causing the SYN packet flood; otherwise it's most likely not a targeted DOS but rather random probing on your service providers subnet looking for unpatched MS RDP vulnerabilities.

"Your Sonicwall is stopping it at your front door; but your service provider can keep it from walking up your driveway."
0
 
LVL 25

Author Comment

by:Tony Giangreco
ID: 39984244
Ok, the RDP server is a Windows 2008 r2 and all Microsoft updates have been applied to it. it' running Symantec Endpoint Protection and we have the RDP port changed so it is not a standard port that's being used.

Do you have any other suggestions that I should look into?
0
 
LVL 25

Author Comment

by:Tony Giangreco
ID: 39991399
I contacted Sonicwall support. The firewall is dropping this traffic as it's designed to do. If it continues, I'll need to contact the ISP and see if they can block it from their side.

Thanks for the info.
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

SHARE your personal details only on a NEED to basis. Take CHARGE and SECURE your IDENTITY. How do I then PROTECT myself and stay in charge of my own Personal details (and) - MY own WAY...
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question