under attack!!!! need help.

Feb 09, 2007 2 Replies
under attack!!!! need help. open original image

Guys,



We have a class B subnet with about 100 active class C networks in 20 different VLANs being routed by a cisco 6509 (sup 720 running IOS). Cisco is routing for all these vlans with a default route out to a set of firewalls (HA) which is connected to our wan provider. I guess thats common setup



now: We are being bombarded with tcp/445 scans from internal infected systems. The virus is somewhat intelligent in that it only scans the class-full subnet that an infected machine is part of. I have blocked some systems with ACLs but I am looking for some way to limit new syns received from a host every second. I don't even know if this is possible at all but I am open for suggestions.



Even when blocked with an ACL, I still see a storm of ARPs and that has me worried too, it already took down a cisco concentrator due to not enough room for cam entries but that was an old hardware so I guess that I can safely assume that other hardware will hold like they have so far.



The firewall that is connected to the cisco never sees this scans because they are local to 6509. I guess we can policy route on the router but I am trying to avoid that due to possible performance hit.



anyone?? the acls are growing HUGH and are hard to keep up with. We have the support people visiting these infected machines and cleaning them up but the infection is spreading faster them we can keep up.



formatting link
Search for SYN:
formatting link
A CAR on each SVI matching "tcp any any syn eq 445" and greatly limiting should help but it can also mess with Windows traffic. I'd at least use CARs with an exceed-action ACL that logs. As you get hits shut down the access port. If you can block NetBIOS across your backbone I'd do that too. If you can.

Get on this list asap:

formatting link
J

If you are under active security attack or believe that you are about to be attacked, contact the Cisco Technical Assistance Center at +1

408 526 7209 or +1 800 553 2447.

formatting link
The TAC dispatch agents will contact the appropriate PSIRT personnel to assist you.

If you have such an incident in progress, need emergency assistance, and do not wish to go through the TAC, you may also contact the PSIRT directly at:

security-alert (at) cisco (dot) com or via telephone at +1 877

228 7302 or +1 408 525 6532.

formatting link
Sincerely,

Brad Reese

formatting link

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required