Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

TCP Syn Host sweep from Pix pool addresses

I am recieving 3030 TCP SYN Host sweep alarms on my IDS4210 v3.1-2-S29 originating from several of my outside addresses. The pix detects no connections are being nated to those address from inside and my internal sensor picks up no sweep signatures. Is it possible to spoof my addresses to perform Sweeps? or am I recieving false alarms.

1 REPLY
New Member

Re: TCP Syn Host sweep from Pix pool addresses

It's probably real sweeps on your address range based on the traffic that is coming out of the PIX (spoofing making assumptions). It couldn't hurt to sniff the outside wire to see what's really going on there. Have you talked to your Cisco tac rep yet?

204
Views
0
Helpful
1
Replies
CreatePlease to create content