Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Under Attack. IP spoof

I have a Cisco ASA 5520 , today a strange thing happened when we were attacked by an IP 64.62.238.46. Below are the logs from ASA

<138>Mar 06 2014 13:52:20 ASA : %ASA-2-106016: Deny IP spoof from (226.181.118.151) to 64.62.238.46 on interface inside

The Specified IP doesnt belong to us or any inside IP.

I have blocked this IP inbound/outbound and i can see the logs , but CPU is still high.

What can I do here

1 REPLY

Re: Under Attack. IP spoof

Hi,

You can use the 'shun' command from ASA privileged EXEC mode to manually block the attacking IP:

# shun 64.62.238.46

Sent from Cisco Technical Support iPhone App

55
Views
0
Helpful
1
Replies