Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

RDP Server Land Attack

Posted on 2014-04-07
7
Medium Priority
?
1,938 Views
Last Modified: 2014-04-10
I've been receiving a few of these alert messages every other day for a week. I have a Sonicwall TZ210W firewall.

The firewall has the latest firmware and appears to be working properly.

04/07/2014 13:32:27.880 - Alert - Intrusion Prevention - Land attack dropped -       x.x.x.x, 11, X1 - x.x.x.x, 11 -

Any idea where to start?
0
Comment
Question by:Tony Giangreco
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
7 Comments
 
LVL 9

Accepted Solution

by:
Lee Ingalls earned 2000 total points
ID: 39984107
I have the same Sonicwall TZ210...

A dropped event is a service that is denied entry into the SonicWALL because it
violates configured or default security policies. No response is returned to the sender of the  event.

"Land Attack Dropped - The SonciWALL has detected and blocked SYN packets whose
source IP addresses are spoofed to be the same as the destination IP addresses".

Review:
Firewall Service Objects
Security Services - Intrusion Prevention - IPS Policies

Are you doing VoIP?
0
 
LVL 25

Author Comment

by:Tony Giangreco
ID: 39984120
So if this starts happening constantly, I'd assume we are having a Doss attack. if not, it's just something to ignore since we don't have an origination IP. Correct?
0
 
LVL 9

Expert Comment

by:Lee Ingalls
ID: 39984139
It's dropping the event without response to the originating sender. I'd say monitor and report to your Service Provider should it persist... since you'd prefer not to have that traffic at all.

I was having similar for a period of time and said something to my provider near contract renewal time and haven't seen them since.

Are you using RDP or Terminal Services through your firewall?
0
Simplifying Server Workload Migrations

This use case outlines the migration challenges that organizations face and how the Acronis AnyData Engine supports physical-to-physical (P2P), physical-to-virtual (P2V), virtual to physical (V2P), and cross-virtual (V2V) migration scenarios to address these challenges.

 
LVL 25

Author Comment

by:Tony Giangreco
ID: 39984150
Yes, we have five servers. 3-DC, 1 Exchange and 1 RDP/Terminal Server
0
 
LVL 9

Expert Comment

by:Lee Ingalls
ID: 39984185
Make sure it's not a mis-configured or unstable RDP/TS client causing the SYN packet flood; otherwise it's most likely not a targeted DOS but rather random probing on your service providers subnet looking for unpatched MS RDP vulnerabilities.

"Your Sonicwall is stopping it at your front door; but your service provider can keep it from walking up your driveway."
0
 
LVL 25

Author Comment

by:Tony Giangreco
ID: 39984244
Ok, the RDP server is a Windows 2008 r2 and all Microsoft updates have been applied to it. it' running Symantec Endpoint Protection and we have the RDP port changed so it is not a standard port that's being used.

Do you have any other suggestions that I should look into?
0
 
LVL 25

Author Comment

by:Tony Giangreco
ID: 39991399
I contacted Sonicwall support. The firewall is dropping this traffic as it's designed to do. If it continues, I'll need to contact the ISP and see if they can block it from their side.

Thanks for the info.
0

Featured Post

Automating Your MSP Business

The road to profitability.
Delivering superior services is key to ensuring customer satisfaction and the consequent long-term relationships that enable MSPs to lock in predictable, recurring revenue. What's the best way to deliver superior service? One word: automation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For anyone that has accidentally used newSID with Server 2008 R2 (like I did) and hasn't been able to get the server running again because you were unlucky (as I was) and had no backups - I was able to get things working by doing a Registry Hive rec…
Resolving an irritating Remote Desktop connection that stops your saved credentials from being used.
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question