Urgent Virus Issue > Block IP Address

Urgent Virus Issue > Block IP Address

NewsGroups | Search | Tools
 comp.dcom.sys.cisco  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Urgent Virus Issue > Block IP Address paul_tomlin 07-21-2008
Posted by on July 21, 2008, 7:49 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
we've got a virus infection and it keeps reinstalling a remote
management tool , I've used some monitoring tools and can see it's
trying to communicate with the public IP 123.119.253.199, I assumed
i'd be able to block this by putting in :

access-list in2out deny ip any host 123.119.253.199
access-list in2out permit ip any any
access-list in2out permit icmp any any
access-group in2out in interface inside

I thought the above lines would resolve it , but I can still see the
virus communicating with that IP address both in and outbound

Anybody have any ideas what i've missed?

Network Magic 20% Off NMEASY coupon code spring banner 468x60
Posted by Brian V on July 21, 2008, 10:03 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

> we've got a virus infection and it keeps reinstalling a remote
> management tool , I've used some monitoring tools and can see it's
> trying to communicate with the public IP 123.119.253.199, I assumed
> i'd be able to block this by putting in :
>
> access-list in2out deny ip any host 123.119.253.199
> access-list in2out permit ip any any
> access-list in2out permit icmp any any
> access-group in2out in interface inside
>
> I thought the above lines would resolve it , but I can still see the
> virus communicating with that IP address both in and outbound
>
> Anybody have any ideas what i've missed?

How about where you applied it, on what interface and in what direction?


Posted by on July 22, 2008, 2:51 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I've read through this
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00801e419a.shtml
and can't see where I could have gone wrong

Anybody got any ideas?


>
>
> > we've got a virus infection and it keeps reinstalling a remote
> > management tool , I've used some monitoring tools and can see it's
> > trying to communicate with the public IP 123.119.253.199, I assumed
> > i'd be able to block this by putting in :
>
> > access-list in2out deny ip any host 123.119.253.199
> > access-list in2out permit ip any any
> > access-list in2out permit icmp any any
> > access-group in2out in interface inside
>
> > I thought the above lines would resolve it , but I can still see the
> > virus communicating with that IP address both in and outbound
>
> > Anybody have any ideas what i've missed?
>
> How about where you applied it, on what interface and in what direction?


Posted by Francois Labreque on July 23, 2008, 12:36 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
paul_tomlin@hotmail.com a écrit :
> we've got a virus infection and it keeps reinstalling a remote
> management tool , I've used some monitoring tools and can see it's
> trying to communicate with the public IP 123.119.253.199, I assumed
> i'd be able to block this by putting in :
>
> access-list in2out deny ip any host 123.119.253.199
> access-list in2out permit ip any any
> access-list in2out permit icmp any any
> access-group in2out in interface inside
>
> I thought the above lines would resolve it , but I can still see the
> virus communicating with that IP address both in and outbound
>
> Anybody have any ideas what i've missed?

If there's an active "xlate" for the infected host(s), new access-lists
won't take effect.

Try issuing a "clear xlate local x.x.x.x" where x.x.x.x is the ip
address of the infected host(s). If you do not have mission critical
traffic through your pix (including the vpn tunnel you're currently
using to access it!), you can just "clear xlate". This will kill all
current connections and force new ones to be rebuilt using the new
in2out access-list.

--
|Francois Labreque | Unfortunately, there's no such thing as a snooze
| flabreque | button on a cat who wants breakfast.
| @ |
| gmail.com | - Unattributed quote from rec.humor.funny

Similar ThreadsPosted
IP Address Block Assignment February 1, 2006, 10:15 am
Block MAC-Address on a 2851 Router? December 6, 2007, 1:52 pm
Nyxem virus February 5, 2006, 3:19 am
MAC Address filter issue September 27, 2006, 8:13 am
virus protection at edge November 27, 2005, 5:58 pm
how can I find Virus using cisco??? September 15, 2006, 12:40 pm
network address translation (nat) issue December 29, 2006, 4:30 am
Does CISCO has virus scanning capabilities? September 6, 2005, 8:17 am
Need Urgent Help April 10, 2006, 6:41 pm
URGENT!!!!!!!!!!!!!!!!!!!!!!!!!!!! July 18, 2006, 12:26 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map