Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Westi on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

attack on port 25

Status
Not open for further replies.

minxca

Technical User
Apr 25, 2003
576
CA
Hi,

I've no knowledge about PIX and I have question: Is it possible to see in syslog if it someone try to attack port 25 (ex: syn attack) since we can't use fixup protocol smtp on PIX? Does the packet go to mail server?

Last week we got Dos attack on port 25 on the ISA server and it blocked the attack but we couldn't send/receive email (send/receive internally OK).

Two days ago, it happened to another mail server behind PIX 515, it can't send/receive internal/external email (all email are in the queue).Router and server's NIC led blinked like crazy . I had't configured syslog, after called the ISP and installed syslog the router works normal so I don't know if my PIX blocked the attack or not. In the log file, I only see block ICMP, HTTP (this PIX is only for Mail, no web).


Thanks,

Winoto
 
You may want to try to configure the built in IDS sensor on the PIX. You may also try to limit the number of embryonic connections on the static translations involving your mail servers this will prevent you from a DOS attack. Check out the links below:



 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top