08-13-2003 06:02 PM - edited 03-09-2019 04:25 AM
Attack of blaster.worm from lan cause router's cpu utilization reaches 70%-80%, besides intalling patches on affected pcs, is there any other work around on cisco router or switch to filter such viruses?
08-14-2003 05:01 PM
you can add ACL to deny these traffic,such as
access-list 110 deny tcp any any eq 135
access-list 110 deny udp any any eq 135
access-list 110 deny tcp any any eq 139
access-list 110 deny udp any any eq 139
access-list 110 deny tcp any any eq 445
access-list 110 deny udp any any eq 139
access-list 110 deny tcp any any eq 593
08-15-2003 05:58 AM
Hi,
I just got this from Cisco that will point you in the right direction.
Title: Cisco Security Notice: W32.BLASTER Worm Mitigation Recommendations
URL: http://www.cisco.com/warp/customer/707/cisco-sn-20030814-blaster.shtml
(available to registered users)
http://www.cisco.com/warp/public/707/cisco-sn-20030814-blaster.shtml
(available to non-registered users)
Posted: August 13, 2003
08-21-2003 07:55 PM
Thanks, new worm was found then.
Cisco Security Notice: Nachi Worm Mitigation Recommendations
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide