Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 

WAN_PING

Our SA540 is showing a lot of records (more than 1 per second) for WAN_PING from all over the world. It is dropping the connection for them. I know there are script kiddies and real deal hackers out there spoofing IP addresses from all over the world and pinging random hosts to pinpoint targets. However, I am wondering how many of you actually have seen it this much? And when you did, what steps did you take to ensure security?

  Also, I am not aware if SA540 has hosts.deny type of thing. If I could automatically deny connections to these hosts for let's say 5 minutes, that would slow them down and will help me better secure my environment.

Everyone's tags (6)
356
Views
0
Helpful
0
Replies
CreatePlease to create content