Security

 View Only
  • 1.  Blocked by ISPt

    Posted Mar 29, 2023 04:44 AM

    Hi all,

    My expertise is mainly WLAN/LAN. I want some help from the security experts.
    I have some firewall experience and experience with the 9004 branch router.

    Problem:

    The ISP (KPN, The Netherlands) blocked me due to DDOS and UDP/53 attacks.

    The conscious setting allows malicious parties to send a small command (via UDP port 53) to your connection. Your connection then returns a much larger response. When a spoofed sender address is provided when running the command, the unsuspecting owner of the spoofed address receives the big reply. A large number of these answers can almost completely shut down his connection. In the security world, we call this a DDoS attack.

    On the ISP modem, UPnP is off, no port-forwarding rules have been created, and I created a DMZ rule that allows all traffic to the edge router.

    Topology:

    9400 branch router does NAT and static routes per VLAN internal to 2930F with a default gateway to the KPN modem

    2930F L3 switch does routing and does have all the VLANs terminated, a static route to 9004.

    2530 L2 switch

    My Wi-Fi is Juniper Mist which is cloud-based.

    Question:

    How can I activate the firewall on the 9400 branch router?

    How can I block DNS, but that DNS outside still works?



  • 2.  RE: Blocked by ISPt

    Posted Mar 29, 2023 04:57 AM




  • 3.  RE: Blocked by ISPt

    Posted Mar 31, 2023 02:24 PM

    Do you have a Policy/ACL on the Interface/VLAN(SVI) connecting you to the ISP? 



    ------------------------------
    Zak Chalupka
    Principal Engineer - HPE Aruba
    ACDX | ACMP | ACSP | ACCP
    wifizak@hpe.com
    ------------------------------



  • 4.  RE: Blocked by ISPt

    Posted Apr 01, 2023 03:03 PM

    Under configuration - services - firewall - ACL -> I've added some ports like 21, 22, 23, 80, 161.
    Not specific an ACL applied to a VLAN or interface.