cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
400
Views
0
Helpful
2
Replies

CSS 11506 triggering 3030 on ASA IPS

kdurrett
Level 3
Level 3

Folks,

The CSS 11506 is triggering tens of thousands hits with signature 3030. We have many other hosts on the campus hitting this signature but the CSS was by far the biggest offender. My question is to verify if the CSS needs to perform these TCP syn sweeps on a constant basis as part of it's maintaining the cache engine? On the CSS we were receiving 12000 miss and about 1500 hits per minute with a savings over the last 60 day of 18%. While trying to tune the IPS, we tuned 3030 to deny the packet inline. After making the change to 3030, we see that out misses on the CSS are down to around 1200 with 300 hits. We than reset the statistics to get a more accurate count, but now there are no hits/misses. We are still receiving tcp requests. Is the tcp syn sweep necessary for the CSS? TIA.

Kurtis

2 Replies 2

mhellman
Level 7
Level 7

It certainly seems plausible that a load balancer would use TCP connections to determine which services in a farm are available. Why don't you just create an event filter for your CSS devices?

kdurrett
Level 3
Level 3

Please ignore this post as I'm gonna have to repost with the actual correct information. As I'm sure I left people scratching there heads wondering what the heck I was talking about. DOH!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card