10-20-2014 05:12 AM - edited 03-11-2019 09:57 PM
Hi all
does the IPS on the ASA protect against syn floods etc ?
10-20-2014 08:21 AM
ASA itself can protect against syn floods dos etc.
try google search cisco asa threat-protection
http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113685-asa-threat-detection.html
10-20-2014 09:37 AM
It says basic threat detection not prevention, do they not prevent ?
10-20-2014 11:23 AM
As noted in the document that Tagir shared, "Scanning Threat Detection can optionally react to an attack by shunning the attacker IP. This makes Scanning Threat Detection the only subset of the Threat Detection feature that can actively affect connections through the ASA."
So we can prevent the traffic from establishing bogus connections via the syn flood method using the command:
threat-detection scanning-threat shun
10-20-2014 03:04 PM
If I installed an ips sensor on the asa, would provide sun flood protection etc?
10-20-2014 03:44 PM
Assuming you mean "SYN flood" then yes - the Cisco IPS sensor covers that attack type. Here is a specific link documenting the IPS signature that covers that attack. When you say "etc" that could mean just about anything so I can't answer that precisely.
Please note that the classic Cisco IPS sensor module for the older ASA 5500 series is no longer sold (since last year).
Cisco will sell you a classic IPS module for the new 5500-X series if you really insist on one but you would be much better served by the ASA with Firepower Services, an option when purchasing or configuring an ASA 5500-X series. That includes the superior Next Generation IPS services acquired last year when Cisco purchased Sourcefire.
(And, yes, the IPS license there will also prevent SYN flood attacks.)
10-20-2014 08:43 PM
another way ASA itself can protect against syn floods etc.
http://ccnpsecurity.blogspot.com/2011/10/configuring-connection-limits-on-cisco_20.html
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: