cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
275
Views
0
Helpful
1
Replies

LAND Attack on my Pix !!!

kunal.shandil
Level 1
Level 1

Hi all,

Today when i saw my syslog i found a lots of strange and similar log mssg on my pix 525 (v7.29(1)) the error mssg is attached however i changed a little details in that jst for security reasons.

LAND attacks seems to happen when a spoofed packet with the SYN flag set comes from a host, with Source ip/port is same as Destination ip/port.

This is highly unlikely in my environment as we have another internal firewall and machines are properly patched.

This PAT config is wht i found on my PIX:-

FW525# sh run | inc PAT_Some_Project name 144.X.Y.Z PAT_Some_Project

global (Outside) 9 PAT_Some_Project netmask 255.255.0.0

FW525#

The netmask shud be /32 I think.

Any suggestions wht is happening here.

regards

Kunal

1 Reply 1

kunal.shandil
Level 1
Level 1

Senior Members any comments ??

regrds

Kunal

Review Cisco Networking products for a $25 gift card