A SERVICE OF

logo

59-5
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter 59 Configuring the Botnet Traffic Filter
Information About the Botnet Traffic Filter
How the Botnet Traffic Filter Works
Figure 59-1 shows how the Botnet Traffic Filter works with the dynamic database plus DNS inspection
with Botnet Traffic Filter snooping.
Figure 59-1 How the Botnet Traffic Filter Works with the Dynamic Database
ASA 5550 40,000
ASA 5580 100,000
Table 59-1 DNS Reverse Lookup Cache Entries per Model
ASA Model Maximum Entries
Security Appliance
DNS
Reverse
Lookup Cache
Infected
Host
Malware Home Site
209.165.201.3
Syslog Server
Dynamic
Database
DNS Server
DNS Snoop
1
DNS Request:
bad.example.com
3
Connection to:
209.165.201.3
2
DNS Reply:
209.165.201.3
Internet
Botnet Traffic
Filter
3b. Send
Syslog Message/Drop Traffic
1a. Match?
3a. Match?
2a. Add
248631