From: Ramy Sisy (ramysisy@inspiredmaster.com)
Date: Mon Jul 21 2008 - 21:02:56 ART
Hi Lucian,
1. You can use any port scan tools or vulnerability assessment tools that
run over TCP ports. There are tons of Linux and Windows tools. (Nmap,
Nessus, portscan, Internet Scanner....)
2. Regarding P2P, If your company is guiding you to test all features before
applying it, so you have to simulate real traffic not just fake connections.
Your company policy is trying to make sure that installed features are
working properly so you have to simulate it properly too.
Think from time/quality prospective as well, how long it will take from you
to find and install P2P simulated applications vs. using real application
and which one will be reliable at the end.
Plus I do not think there is P2P simulation software.
BEST REGARDS,
RAMY SISY, CCIE X 2 (SECURITY, ROUTING/SWITCHING)#17321, CCSI#30417
CCIE PROGRAM MANAGER
INSPIRED MASTER
INSPIRING CREATIVE THINKING ....
WWW.INSPIREDMASTER.COM
E. RAMYSISY@INSPIREDMASTER.COM
-----Original Message-----
From: nobody@groupstudy.com [mailto:nobody@groupstudy.com] On Behalf Of Ccie
Go
Sent: Monday, July 21, 2008 2:22 PM
To: ccielab@groupstudy.com
Cc: goccie30@yahoo.com
Subject: DoS prevention / peer-to-peer testing
HI @All,
1.I want to protect one file server which is accessible from
internet and which is frequently undertaking Tcp SYN DoS attacks from
internet.
I want to use TCP Intercept in "intercept mode" but before turning
on this feature I would like to check the impact on the Border router which
will be configured to intercept all this TCPSYN flooding!
Could you point me
to a good application which I can use to generate a high amount of TCP SYN
packets on differet port ranges!!
2. I'm in charge to find a solution which
stop all peer-to-peer file transfer for all known protocolsThat's stright
forward:
class-map match-any nbar-discovery
match protocol gnutella
match
protocol kazaa2
match protocol napster
match protocol fasttrack
match protocol
novadigm
match protocol edonkey
match protocol bittorrent
!
!
policy-map P2P
class nbar-discovery
drop
Now the problem I have is the company policy
which "guide us" that we have to test all the features/functionalityes
before
implementing them in the network.
The question I have: is there any way to
test/match this protocols without installing Bittorent, DC++,and
transferring
the files?! I mean, is there any P2P traffic generator/simulator I might use
for this testing??
Thanks in advance for your sugestion.
Lucian
This archive was generated by hypermail 2.1.4 : Mon Aug 04 2008 - 06:11:56 ART