protect against UDP diagnostic port attacks?

From: Hoyle, Anthony (AL) (ALHoyle@dow.com)
Date: Fri Dec 12 2003 - 09:14:46 GMT-3


Anyone know how to protect against this. What is this? Talking /w a colleagues he believes it may be IDS scanning for viruses on end systems...or something like that From the
TAC case I'm working on it seems like it's hitting a WAN router and causing unnecessary transmission loads. I was thinking rate-limiting maybe using flow based WRED to throttle this,
-but that would be all UDP traffic and that may not be good. This is really weird, I have never heard of this before...I am open to ANY suggestions...by the way, there is a queueing strategy
On that particular router-

Anthony Hoyle



This archive was generated by hypermail 2.1.4 : Sat Jan 03 2004 - 08:25:39 GMT-3