cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1354
Views
4
Helpful
4
Replies

A syn flood attack

pesanchez2002
Level 1
Level 1

hi,

I receive the next message in unix, my webserver, What the meaning?

What i can do?

"warning: high tcp connect timeout rate! system (port 443) may be under a syn flood attack"

4 Replies 4

Giuseppe Larosa
Hall of Fame
Hall of Fame

Hello Pedro,

if you have an edge router you can use TCP intercept feature to defend your server.

see

http://www.cisco.com/en/US/docs/ios/sec_data_plane/configuration/guide/sec_cfg_tcp_intercpt_ps6350_TSD_Products_Configuration_Guide_Chapter.html

Hope to help

Giuseppe

Thanks by your answer,

I don't have router edge.

I have the next connection

pix---sw---webserver

!

!

internet

Internet connect with sw

Hello Pedro,

if the pix is not on the path to/from internet you cannot do anything.

You should have the webserver on an DMZ (third leg/interface) of pix.

doing so you could protect the server.

By the way, the message says:

"warning: high tcp connect timeout rate! system (port 443) may be under a syn flood attack"

port 443 that is

Protocol / Name: https

If you don't need https you can close the service on the web server.

if you are using https this cannot be done.

I would suggest you to review the DMZ and to have it protected by the pix that can provide features similar to TCP intercept.

Hope to help

Giuseppe

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card