pacman662860
IS-IT--Management
Could somebody shed some light on this for me. I just got our PIX configured and running and I built a static NAT for an inside host (172.25.25.200) which is NAT'd to 66.172.157.200 and the log is showing a constant flow of thes connection attemtps (SYN). I tried to have them dropped by adding an access-list entry (access-list 100 deny ip any 118.0.0.0 255.0.0.0) but am still seeing the log flood with countless attemts at sequentialling increasing ports. I assume this a a SYN DOS or flood, no? Can anyone give me some advice on how to stop please?
302014: Teardown TCP connection 1912035 for outside:118.81.139.105/135 to inside
:172.25.25.200/4337 duration 0:02:01 bytes 0 SYN Timeout
302014: Teardown TCP connection 1912036 for outside:118.81.139.106/135 to inside
:172.25.25.200/4338 duration 0:02:01 bytes 0 SYN Timeout
302014: Teardown TCP connection 1912037 for outside:118.81.139.107/135 to inside
:172.25.25.200/4339 duration 0:02:01 bytes 0 SYN Timeout
302014: Teardown TCP connection 1912038 for outside:118.81.139.108/135 to inside
:172.25.25.200/4340 duration 0:02:01 bytes 0 SYN Timeout
302014: Teardown TCP connection 1912039 for outside:118.81.139.109/135 to inside
:172.25.25.200/4341 duration 0:02:01 bytes 0 SYN Timeout
302013: Built outbound TCP connection 1913394 for outside:118.81.144.185/135 (11
8.81.144.185/135) to inside:172.25.25.200/1750 (66.172.157.200/1750)
302013: Built outbound TCP connection 1913395 for outside:118.81.144.186/135 (11
8.81.144.186/135) to inside:172.25.25.200/1751 (66.172.157.200/1751)
302013: Built outbound TCP connection 1913396 for outside:118.81.144.187/135 (11
8.81.144.187/135) to inside:172.25.25.200/1752 (66.172.157.200/1752)
302014: Teardown TCP connection 1912035 for outside:118.81.139.105/135 to inside
:172.25.25.200/4337 duration 0:02:01 bytes 0 SYN Timeout
302014: Teardown TCP connection 1912036 for outside:118.81.139.106/135 to inside
:172.25.25.200/4338 duration 0:02:01 bytes 0 SYN Timeout
302014: Teardown TCP connection 1912037 for outside:118.81.139.107/135 to inside
:172.25.25.200/4339 duration 0:02:01 bytes 0 SYN Timeout
302014: Teardown TCP connection 1912038 for outside:118.81.139.108/135 to inside
:172.25.25.200/4340 duration 0:02:01 bytes 0 SYN Timeout
302014: Teardown TCP connection 1912039 for outside:118.81.139.109/135 to inside
:172.25.25.200/4341 duration 0:02:01 bytes 0 SYN Timeout
302013: Built outbound TCP connection 1913394 for outside:118.81.144.185/135 (11
8.81.144.185/135) to inside:172.25.25.200/1750 (66.172.157.200/1750)
302013: Built outbound TCP connection 1913395 for outside:118.81.144.186/135 (11
8.81.144.186/135) to inside:172.25.25.200/1751 (66.172.157.200/1751)
302013: Built outbound TCP connection 1913396 for outside:118.81.144.187/135 (11
8.81.144.187/135) to inside:172.25.25.200/1752 (66.172.157.200/1752)