Hi there,
From my PIX506 PDM, I plotted a graph "IDS, DNS Attacks", in which I got a blue line keep on raising up to 6K packets. From the legend blue line is "All Records".
I got a DNS server behind PIX which allow for public access, is this blue line a normal one? Or it really told me that my DNS server was being attack? If it was really being attack, how can I retrieve more info from PIX?
Thanks so much for your help!
From my PIX506 PDM, I plotted a graph "IDS, DNS Attacks", in which I got a blue line keep on raising up to 6K packets. From the legend blue line is "All Records".
I got a DNS server behind PIX which allow for public access, is this blue line a normal one? Or it really told me that my DNS server was being attack? If it was really being attack, how can I retrieve more info from PIX?
Thanks so much for your help!