Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

limiting embryonic connections outbound issue.

nat 1 0.0.0.0 0.0.0.0 0 10

does not limit inbound users from having more than 10 saA's ie an infected host could still generate hundreds of SYNs to non existant hosts outbound.

ie bad host would generate 1 initial SYN session request to 100 different non existant IP addresses.

Will the next Version address this issue, is it also possible to add a autoshun capability if a host violates an internal host violates outbound embryonic limit rule. adding this feature to internal hosts violating connection limits would also be nice :)

1 REPLY

Re: limiting embryonic connections outbound issue.

I've tried syn-flood attack. Attacker sent 30000 pps.

pix cpu utilisation 99%.

it dosn't matter have you blocked access-list, shun, or no translatinon. PIX cpu utilisation 99%.

94
Views
0
Helpful
1
Replies
CreatePlease login to create content