cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
504
Views
0
Helpful
2
Replies

CSS DoS

tony.h
Level 1
Level 1

Is DoS protection a built-in feature of CSS11500?

How to configure DoS and how to block intrusion from the output of show dos ?

Thanks,

tony

2 Replies 2

pgolding
Level 1
Level 1

DoS is built in to the CSS, there is no configuration for it expect for snmp trap generation for DoS detection. CSS is not a firewall, its DoS detection is limited to obvious things, such as source and destination addresses being the same - land, smurf, half open syn, loopback or broadcast addresses, source address that the box owns etc.

I have found that false DoS error alerts are generated when my load balanced servers try to open connections to other servers that are down. The CSS sees a device sending SYN packets for connections that never open.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: