Cisco Systems how to stop denial of service in a 1700 router

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
how to stop denial of service in a 1700 router jcharth 09-02-05
Posted by on September 2, 2005, 6:09 pm
Please log in for more thread options
Hello My router is getting a flood of udps, the error could be a denial
of service attack. what do i do the block it? I see a lot of large size
udp packets. Could it be a wrong subnet mask.
Thanks


Posted by www.BradReese.Com on September 3, 2005, 12:09 pm
Please log in for more thread options
You may wish to investigate Cisco Security Strategies for Attack
Defense, Tracking or Mitigation:

http://www.bradreese.com/cisco-security-advisories.htm#STRATEGIES

Hope this helps.

Brad Reese
BradReese.Com Cisco Repair Service Experts
http://www.bradreese.com/index.htm#EXPERTS
1293 Hendersonville Road, Suite 17
Asheville, North Carolina USA 28803
USA & Canada: 877-549-2680
International: 828-277-7272


Posted by Igor Mamuzic on September 3, 2005, 12:10 pm
Please log in for more thread options
You need first do detect what kind of UDP traffic it's about (what udp ports
are used?)...

You can discover this (if you don't have netflow analyzer) by creating an
ACL as follows (ACL number is only an example, please check 'show
access-list 100' output to find out if there is already ACL 100 configured
on your router):
access-list 100 permit udp any any log
access-list 100 permit ip any any

Place this ACL on the interface where this susspicious traffic enters your
router...

Then execute 'show log' and you'll see what kind of udp traffic it's about.
Then you can create adequate ACL that will block that traffic...

B.R.
I

> Hello My router is getting a flood of udps, the error could be a denial
> of service attack. what do i do the block it? I see a lot of large size
> udp packets. Could it be a wrong subnet mask.
> Thanks
>



Similar ThreadsPosted
how to stop denial of service in a 1700 router September 2, 2005, 6:09 pm
ISDN - How to stop a router dialling up on bootup September 27, 2006, 2:47 pm
WebVPN and remote admin denial May 30, 2007, 10:05 am
A non-Cisco router, BDCOM 1700 Router Series June 28, 2008, 4:27 am
Cisco 1700 Router July 25, 2008, 8:00 am
Very strange ftp problems through 1700 router. August 14, 2005, 2:12 pm
1700 Router - creating a dot1q VLAN subinterface July 5, 2007, 9:49 pm
cant ping when adding secondary ip to 1 fastethernet interface on 1700 router August 17, 2005, 12:14 pm
configuration of a router Cisco 1700 on ADSL max of a wide-area network February 10, 2006, 4:49 am
STOP what you’re doing - It doesn’t work! 6IU7 July 28, 2006, 5:28 pm
internal name servers stop recursive lookups October 24, 2005, 8:36 am
Your One Stop Shop for Data & Voice Hardware February 1, 2007, 5:32 pm
Web Browser Stop Working after VPN Client Installation March 26, 2008, 2:17 pm
RADIUS stop packet guaranteed delivery May 21, 2008, 9:51 am
Cisco 1700 July 27, 2006, 9:24 pm