cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
218
Views
0
Helpful
1
Replies

20K Messages a Second ... Incredible

scheikhnajib
Level 1
Level 1

Hi,

Suddenly, the CPU utilization on my PIX 515E running PIX OS 7.0 has risen to 99%. After alot of troubleshooting, I implemented an IDS policy on the inside interface and figured out that one of the internal machines is triggering signature ID 2001 (ICMP Unreachables) at a rediculous rate (around 20,000 messages a second). I havn't seen such a IDS counter in my whole life ...

Anyway, my server guy is still looking ath the machine, but does anyone has any idea what might cause a machine to send such messages at that rate ???

By the way, the destination of the messages is the IP address of the inside interface of the PIX.

Thanks.

Salem.

1 Reply 1

s-doyle
Level 3
Level 3

ICMP Host Unreachable datagrams may be used to bypass packet filter security policies as they are rarely filtered in either incoming or outgoing traffic. May be used to perform denial of service attacks.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: