Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

20K Messages a Second ... Incredible

Hi,

Suddenly, the CPU utilization on my PIX 515E running PIX OS 7.0 has risen to 99%. After alot of troubleshooting, I implemented an IDS policy on the inside interface and figured out that one of the internal machines is triggering signature ID 2001 (ICMP Unreachables) at a rediculous rate (around 20,000 messages a second). I havn't seen such a IDS counter in my whole life ...

Anyway, my server guy is still looking ath the machine, but does anyone has any idea what might cause a machine to send such messages at that rate ???

By the way, the destination of the messages is the IP address of the inside interface of the PIX.

Thanks.

Salem.

1 REPLY
New Member

Re: 20K Messages a Second ... Incredible

ICMP Host Unreachable datagrams may be used to bypass packet filter security policies as they are rarely filtered in either incoming or outgoing traffic. May be used to perform denial of service attacks.

105
Views
0
Helpful
1
Replies