Sitemap

Amicuk Programming Answers

Duplicate SYN attacks from Outside to Outside

-0001-11-30   Views:2

Advertisement

Hi Everyone, We have an FTP server that sits in our DMZ.  This Server has a DMZ interface and an external interface.  When trying to access the server from the internet on its external address i am getting alot of Duplicate SYN attacks.  They seem to

Hi Everyone,
We have an FTP server that sits in our DMZ.  This Server has a DMZ interface and an external interface.  When trying to access the server from the internet on its external address i am getting alot of Duplicate SYN attacks.  They seem to be coming all from the same source and port to the same destination and port.
As part of the testing i first took out any references to the FTP server in my Access rules on the ASA.  I then tried to FTP to the server from an outside internet connection and as expected get the following in the log:
4
Mar 01 2013
10:23:18
194.80.130.xx
46867
78.24.112.XX
21
Deny tcp src outside:194.80.130.XX/46867 dst outside:78.24.112.XX/21 by access-group "outside_access_in" [0x0, 0x0]
I then highlighted this entry and created an access rule for it (but changed the source port to any rather than a specific one).  When i then try and FTP to the server i get lots of SYN attacks which says the following:
4
Mar 01 2013
10:27:29
194.80.130.XX
46973
78.24.112.XX
21
Duplicate TCP SYN from outside:194.80.130.XX/46973 to outside:78.24.112.XX/21 with different initial sequence number
I am not sure why I am getting duplicate SYN attacks.  I have similar servers in the DMZ that do the same thing and they seem to be working fine.  I am pretty sure this is not actually a DOS attack.  I also have spoken to the team who manage the server and they have confirmed that the external IP is setup correctly on the server (its not that the external IP does not exist and just loops).
There is also NAT'ing setup on the ASA that NATs the dmz IP to the external IP and vice versa.
I have also noticed that whenever i create a new rule on the outside interface on my ASA it automatically adds the same descripton from another rule on the outside interface.  What does this mean?  Why could it be copying a description from anothe rule?
Your advice would be much appreciated.

The replay answer
Advertisement
Output from packet-tracer to outside address 78.24.112.xx 
It seems as though the NAT to the DMZ address is just not working.  I have set a NAT rule up "before network object NAT" rule and also set a simple object NAT, but still getting the error.
Phase: 1
Type: ACCESS-LIST
Subtype: log
Result: ALLOW
Config:
access-group outside_access_in in interface outside
access-list outside_access_in extended permit object-group DM_INLINE_SERVICE_7 any object csdpr1ft-ext
object-group service DM_INLINE_SERVICE_7
service-object tcp destination eq ssh
service-object ip
service-object tcp destination eq ftp
Additional Information:
Phase: 2
Type: IP-OPTIONS
Subtype:
Result: ALLOW
Config:
Additional Information:
Phase: 3
Type: INSPECT
Subtype: inspect-ftp
Result: ALLOW
Config:
class-map inspection_default
match default-inspection-traffic
policy-map global_policy
class inspection_default
  inspect ftp
service-policy global_policy global
Additional Information:
Phase: 4
Type: FOVER
Subtype: standby-update
Result: ALLOW
Config:
Additional Information:
Phase: 5
Type: VPN
Subtype: ipsec-tunnel-flow
Result: ALLOW
Config:
Additional Information:
Phase: 6
Type: IP-OPTIONS
Subtype:
Result: ALLOW
Config:
Additional Information:
Phase: 7
Type: FLOW-CREATION
Subtype:
Result: ALLOW
Config:
Additional Information:
New flow created with id 26135657, packet dispatched to next module
Result:
input-interface: outside
input-status: up
input-line-status: up
Action: allow

Go to See the other 13 answers

Hot
Lightroom does not recognize the raw files (necs?) coming in from my Nikon AW1. It loads them as jpegs. I know it is possible to update Lightroom so it knows my Nikon but I can't get it to work. I would like files to be loaded as .dng.update by downl [More]
Dear all, I have a sales business scenario, but I don't know how to implement in SAP. The business scenario is as follows: - Company A will sell a batch goods to its customer B. But, this is a large sales project. So, A should create a series of sale [More]
Is there any way to scan a document to a MS Word Document?? Right now the only option I have is a PDF file and that doesn't convert very to a Word Doc. This question was solved. View Solution.THANKS FOR HELPING.Read other 3 answers [More]
When we try to create a BP as vendor, we dont see XML as the output in Send Medium in the Co. code tab. Is there anything to be configured so that XML shows up as the output medium ? We only see Fax, Mail, Print. -BakuleshHi Please go through this -> [More]
Dear all, 10.2.0.2 on linux We are getting the below error in alert log and synchronization stopped ORA-00922: missing or invalid option Tue Oct 11 20:40:41 2011 PRMX: Alter session failed: ORA-02097: parameter cannot be modified because specified va [More]
I'm trying to implement the white paper on using business events to populate the delta queue.  The question I have is can I do this with the WRPL table?  What business event would this be? Thanks in advance, MarkHi Amit, Thanks for your help. I did i [More]
I inserted a clean Spry Tabbed Panel into a virtually empty HTML page (no content). I have a content div (624 px , float left) and sidebar (336 px, float right). When I insert the tabbed panel widget into the sidebar, the Spry Title Tabs go or float [More]
Hello, I have been looking through some of the documentation on the Adobe web site and I have read several posts that have answered some of my questions but I just want to be certain that Contribute is the product that I need, or rather my client nee [More]
I am trying to import a movie from my camcorder to my mac to begin a movie project. As instructed, my camcorder is on play mode, i click on "create a new project". I name a project and click "create". You are then supposed to get a blu [More]
I was using PSE 8 earlier in the day with no problems. I tried to open the editor and got a crash report and program shut down. Organizer works fine. I have been searching for a solution for a couple of day and have applied several suggested fixes, w [More]