Question for you Cisco gurus

LoStMaTt

2[H]4U
Joined
Feb 26, 2003
Messages
3,180
I have just started to really dig into Cisco eqiupment. I recently implented IPS on our router and discovered a large amount of Torrent activity on the network which I quickly took care of. That sped up internet access considerably but....

I just came across this:

2157:1 ICMP Hard Error DoS Source IP **** Destination IP **** 45685 <---- WOA WOA

I click on update every 30 seconds or so and the # jumps up by 10-15. Here is the thing though, the Destination IP that is listed from the attack is referring to a member server that is no longer online nor even plugged in.

So, what course of action should be done about the above DoS "attack" if it is infact the real deal.
 
If they're all coming from the same source, I'd just modify your ACL to drop that IP address once it hits your router. I tried Googling for that IPS signature but it didn't really turn up much.
 
You might nullroute the source, cheaper on routers then ACLs from my understanding.
 
Back
Top