Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

RDP Server Land Attack

Posted on 2014-04-07
7
Medium Priority
?
1,991 Views
Last Modified: 2014-04-10
I've been receiving a few of these alert messages every other day for a week. I have a Sonicwall TZ210W firewall.

The firewall has the latest firmware and appears to be working properly.

04/07/2014 13:32:27.880 - Alert - Intrusion Prevention - Land attack dropped -       x.x.x.x, 11, X1 - x.x.x.x, 11 -

Any idea where to start?
0
Comment
Question by:Tony Giangreco
  • 4
  • 3
7 Comments
 
LVL 9

Accepted Solution

by:
Lee Ingalls earned 2000 total points
ID: 39984107
I have the same Sonicwall TZ210...

A dropped event is a service that is denied entry into the SonicWALL because it
violates configured or default security policies. No response is returned to the sender of the  event.

"Land Attack Dropped - The SonciWALL has detected and blocked SYN packets whose
source IP addresses are spoofed to be the same as the destination IP addresses".

Review:
Firewall Service Objects
Security Services - Intrusion Prevention - IPS Policies

Are you doing VoIP?
0
 
LVL 25

Author Comment

by:Tony Giangreco
ID: 39984120
So if this starts happening constantly, I'd assume we are having a Doss attack. if not, it's just something to ignore since we don't have an origination IP. Correct?
0
 
LVL 9

Expert Comment

by:Lee Ingalls
ID: 39984139
It's dropping the event without response to the originating sender. I'd say monitor and report to your Service Provider should it persist... since you'd prefer not to have that traffic at all.

I was having similar for a period of time and said something to my provider near contract renewal time and haven't seen them since.

Are you using RDP or Terminal Services through your firewall?
0
Get your Conversational Ransomware Defense e‑book

This e-book gives you an insight into the ransomware threat and reviews the fundamentals of top-notch ransomware preparedness and recovery. To help you protect yourself and your organization. The initial infection may be inevitable, so the best protection is to be fully prepared.

 
LVL 25

Author Comment

by:Tony Giangreco
ID: 39984150
Yes, we have five servers. 3-DC, 1 Exchange and 1 RDP/Terminal Server
0
 
LVL 9

Expert Comment

by:Lee Ingalls
ID: 39984185
Make sure it's not a mis-configured or unstable RDP/TS client causing the SYN packet flood; otherwise it's most likely not a targeted DOS but rather random probing on your service providers subnet looking for unpatched MS RDP vulnerabilities.

"Your Sonicwall is stopping it at your front door; but your service provider can keep it from walking up your driveway."
0
 
LVL 25

Author Comment

by:Tony Giangreco
ID: 39984244
Ok, the RDP server is a Windows 2008 r2 and all Microsoft updates have been applied to it. it' running Symantec Endpoint Protection and we have the RDP port changed so it is not a standard port that's being used.

Do you have any other suggestions that I should look into?
0
 
LVL 25

Author Comment

by:Tony Giangreco
ID: 39991399
I contacted Sonicwall support. The firewall is dropping this traffic as it's designed to do. If it continues, I'll need to contact the ISP and see if they can block it from their side.

Thanks for the info.
0

Featured Post

Threat Trends for MSPs to Watch

See the findings.
Despite its humble beginnings, phishing has come a long way since those first crudely constructed emails. Today, phishing sites can appear and disappear in the length of a coffee break, and it takes more than a little know-how to keep your clients secure.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A procedure for exporting installed hotfix details of remote computers using powershell
This article explains how to install and use the NTBackup utility that comes with Windows Server.
This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conne…
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…

782 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question