944,085 Members | Top Members by Rank

  • Networking Discussion Thread
  • Unsolved
  • Views: 3554
  • Networking RSS
Nov 1st, 2006
0

How do I stop a DOS?

Expand Post »
Okay, I know I probably can't stop it, but it seemed like a good title.

I am a junior systems analyst and I monitor Cisco routers and switches. On one of my routers, a Cisco 7200 series running IOS 12.2(15)T17, I have been monitoring a Denial of Service attack for a few weeks now. Someone or some people have it out for us, it seems, and are not only overloading my router's cpu (now runs between 75% and 100%) but they are spoofing IPs to do it. I've placed several blocks at the top of an access list and have even had some hitters big enough to email a few abuse@isp.com addresses. This only does so much. The router is a gateway router so the traffic isn't getting into the network and clogging it up, but the traffic still has to go through the ACLs on the router which uses processing which in turn causes problems for legit traffic trying to come in and out. I guess my question is: is there an easier way to work with this other than spending an hour a day analyzing ip cache flows and placing blocks on a list?
Similar Threads
Reputation Points: 10
Solved Threads: 0
Newbie Poster
tuttlem is offline Offline
4 posts
since Nov 2006
Oct 11th, 2008
0

Re: How do I stop a DOS?

Hi Tuttlem;

I work as a data centre manager for an organisation with web facing e-commerce gateways and we recently came under attack from both DOS and DDOS attacks...
These combined syn floods, tcp stacks, sql injects and all manner of unwanted traffic that eventually knocked out my IPS resources.

After trying a numer of very expensive cloud based solutions ; we eventually opted for a dedicated solution which sits in front of our interfaces in a HA pair.

This product was WS1000 by Webscreen and because it uses " live intelligence", within 30 mins of their technican attaching the appliance; we were back up and running bacuase we could specify exactly what type of traffic we wanted to let through.
Last edited by SEANDSE; Oct 11th, 2008 at 8:17 pm.
Reputation Points: 10
Solved Threads: 0
Newbie Poster
SEANDSE is offline Offline
1 posts
since Oct 2008
Oct 18th, 2008
0

Re: How do I stop a DOS?

Click to Expand / Collapse  Quote originally posted by tuttlem ...
Okay, I know I probably can't stop it, but it seemed like a good title.
you might get something out of this...

http://www.gcn.com/print/vol20_no17/4573-1.html#
Reputation Points: 343
Solved Threads: 40
Nearly a Posting Virtuoso
zeroth is offline Offline
1,220 posts
since Mar 2005

This thread is more than three months old

No one has posted to this discussion for at least three months. Please let old threads die and do not reply to them unless you feel you have something new and valuable to contribute that absolutely must be added to make the discussion complete. Otherwise, please start a new thread in this forum instead.
Message:
Previous Thread in Networking Forum Timeline: Internal and External Workgroup merging
Next Thread in Networking Forum Timeline: iptables -m recent conflicting





About Us | Contact Us | Advertise | Acceptable Use Policy
Forum Index | Build Custom RSS Feed


Follow us on Twitter


© 2011 DaniWeb® LLC