DOS Attack?

From: Shawn Wall (sjwall_at_shaw.ca)
Date: 11/25/04

  • Next message: Andrew Shore: "RE: cisco IOS firewall terminating pptp"
    Date: Wed, 24 Nov 2004 19:22:40 -0700
    To: security-basics@securityfocus.com
    
    

    Hi List,

    I'm currently experiencing network outages due to what appears to be DOS
    attacks. I'm running a wireless ISP using a Cisco 2611 and CBAC and I have a
    /24 public address range. During the outage I can see traffic from a single
    external host sending thousands of packets to a single internal host. I
    don't have port 80 inbound open in my ACLs so I don't understand how the
    external host is even able to contact the internal host to begin with.
    Secondly, how is it possible for an attack on 1 internal host to cripple the
    rest of my network? Any feedback would be welcome. Thanks.

    shawn
     


  • Next message: Andrew Shore: "RE: cisco IOS firewall terminating pptp"

    Relevant Pages

    • Re: DOS Attack?
      ... >I'm currently experiencing network outages due to what appears to be DOS ... >attacks. ... >external host is even able to contact the internal host to begin with. ...
      (Security-Basics)
    • Re: DOS Attack?
      ... > I'm currently experiencing network outages due to what appears to be DOS ... > external host is even able to contact the internal host to begin with. ... Smells like spyware in your internal machine. ...
      (Security-Basics)
    • Re: VPN behind not managed Firewall-1: can it be done?
      ... > Try running a port scan from outside of the FW against a node inside. ... > you can (doubtful) than you can do anything you like. ... allow a portscan from an external host to an internal host. ...
      (comp.security.firewalls)