Cisco ASA 5505 Configuration Manual page 1124

Asa 5500 series
Hide thumbs Also See for ASA 5505:
Table of Contents

Advertisement

Configuring IP Audit for Basic IPS Support
Table 52-1
Signature IDs and System Message Numbers (continued)
Signature
Message
ID
Number
Signature Title
3042
400028
TCP FIN only flags
3153
400029
FTP Improper Address Specified
3154
400030
FTP Improper Port Specified
4050
400031
UDP Bomb attack
4051
400032
UDP Snork attack
4052
400033
UDP Chargen DoS attack
6050
400034
DNS HINFO Request
6051
400035
DNS Zone Transfer
6052
400036
DNS Zone Transfer from High Port
6053
400037
DNS Request for All Records
6100
400038
RPC Port Registration
6101
400039
RPC Port Unregistration
6102
400040
RPC Dump
6103
400041
Proxied RPC Request
6150
400042
ypserv (YP server daemon) Portmap
Request
6151
400043
ypbind (YP bind daemon) Portmap
Request
Cisco ASA 5500 Series Configuration Guide using ASDM
52-10
Signature Type Description
Attack
Triggers when a single orphaned TCP FIN
packet is sent to a privileged port (having port
number less than 1024) on a specific host.
Informational
Triggers if a port command is issued with an
address that is not the same as the requesting
host.
Informational
Triggers if a port command is issued with a
data port specified that is <1024 or >65535.
Attack
Triggers when the UDP length specified is
less than the IP length specified. This
malformed packet type is associated with a
denial of service attempt.
Attack
Triggers when a UDP packet with a source
port of either 135, 7, or 19 and a destination
port of 135 is detected.
Attack
This signature triggers when a UDP packet is
detected with a source port of 7 and a
destination port of 19.
Informational
Triggers on an attempt to access HINFO
records from a DNS server.
Informational
Triggers on normal DNS zone transfers, in
which the source port is 53.
Informational
Triggers on an illegitimate DNS zone transfer,
in which the source port is not equal to 53.
Informational
Triggers on a DNS request for all records.
Informational
Triggers when attempts are made to register
new RPC services on a target host.
Informational
Triggers when attempts are made to
unregister existing RPC services on a target
host.
Informational
Triggers when an RPC dump request is issued
to a target host.
Attack
Triggers when a proxied RPC request is sent
to the portmapper of a target host.
Informational
Triggers when a request is made to the
portmapper for the YP server daemon
(ypserv) port.
Informational
Triggers when a request is made to the
portmapper for the YP bind daemon (ypbind)
port.
Chapter 52
Using Protection Tools
OL-20339-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5510Asa 5540Asa 5520Asa 5550Asa 5580

Table of Contents