Thanks Steve for valuable advice!! But i am not able to figure it out here whether its a DOS attack or its an alert. But the thing is that i am countinously getting these logs.
2015-08-17 16:53:36 system alert 00010 Land attack! From x.x.x.75 to
x.x.x.75, proto 6 (zone Untrust,
int aggregate1). Occurred 1 times.
2015-08-17 16:53:31 system alert 00010 Land attack! From x.x.x.75 to
x.x.x.75, proto 6 (zone Untrust,
int aggregate1). Occurred 1 times.
2015-08-17 16:53:27 system alert 00010 Land attack! From x.x.x.75 to
x.x.x.75, proto 6 (zone Untrust,
int aggregate1). Occurred 1 times.
2015-08-17 16:52:21 system alert 00010 Land attack! From x.x.x.40 to
x.x.x.40, proto 6 (zone Untrust,
int aggregate1). Occurred 1 times.
2015-08-17 16:52:20 system alert 00010 Land attack! From x.x.x.31 to
x.x.x.31, proto 6 (zone Untrust,
int aggregate1). Occurred 1 times.
2015-08-17 16:52:15 system alert 00010 Land attack! From x.x.x.40 to
x.x.x.40, proto 6 (zone Untrust,
int aggregate1). Occurred 1 times.
2015-08-17 16:52:12 system alert 00010 Land attack! From x.x.x.40 to
x.x.x.40, proto 6 (zone Untrust,
int aggregate1). Occurred 1 times.
2015-08-17 16:52:12 system alert 00010 Land attack! From x.x.x.31 to
x.x.x.31, proto 6 (zone Untrust,
int aggregate1). Occurred 1 times.
2015-08-17 16:51:51 system alert 00010 Land attack! From x.x.x.40 to
x.x.x.40, proto 6 (zone Untrust,
int aggregate1). Occurred 1 times.
2015-08-17 16:51:45 system alert 00010 Land attack! From x.x.x.40 to
x.x.x.40, proto 6 (zone Untrust,
int aggregate1). Occurred 1 times.
Here x.x.x is ist 3 octets. All these ips are from the DIP pool which is created over the same Firewall.
Here is DIP created on FW, and all the logs that are generating over the firewall having the same source and destination.
set interface aggregate1 ext ip x.x.x.1 255.255.255.0 dip 5 x.x.x.5 x.x.x.5
set interface aggregate1 ext ip x.x.x.1 255.255.255.0 dip 6 x.x.x.6 x.x.x.10
set interface aggregate1 ext ip x.x.x.1 255.255.255.0 dip 7 x.x.x.11 x.x.x.15
set interface aggregate1 ext ip x.x.x.1 255.255.255.0 dip 8 x.x.x.16 x.x.x.20
set interface aggregate1 ext ip x.x.x.1 255.255.255.0 dip 9 x.x.x.21 x.x.x.25
set interface aggregate1 ext ip x.x.x.1 255.255.255.0 dip 10 x.x.x.26 x.x.x.30
set interface aggregate1 ext ip x.x.x.1 255.255.255.0 dip 11 x.x.x.31 x.x.x.35
set interface aggregate1 ext ip x.x.x.1 255.255.255.0 dip 12 x.x.x.36 x.x.x.40
set interface aggregate1 ext ip x.x.x.1 255.255.255.0 dip 13 x.x.x.41 x.x.x.45
set interface aggregate1 ext ip x.x.x.1 255.255.255.0 dip 14 x.x.x.46 x.x.x.47
set interface aggregate1 ext ip x.x.x.1 255.255.255.0 dip 15 x.x.x.55 x.x.x.55
set interface aggregate1 ext ip x.x.x.1 255.255.255.0 dip 16 x.x.x.56 x.x.x.60
set interface aggregate1 ext ip x.x.x.1 255.255.255.0 dip 17 x.x.x.61 x.x.x.65
set interface aggregate1 ext ip x.x.x.1 255.255.255.0 dip 18 x.x.x.66 x.x.x.70
set interface aggregate1 ext ip x.x.x.1 255.255.255.0 dip 19 x.x.x.71 x.x.x.75
set interface aggregate1 ext ip x.x.x.1 255.255.255.0 dip 20 x.x.x.76 x.x.x.80
set interface aggregate1 ext ip x.x.x.1 255.255.255.0 dip 21 x.x.x.81 x.x.x.85
set interface aggregate1 ext ip x.x.x.1 255.255.255.0 dip 22 x.x.x.86 x.x.x.90
set interface aggregate1 ext ip x.x.x.1 255.255.255.0 dip 26 x.x.x.96 x.x.x.100
set interface aggregate1 ext ip x.x.x.1 255.255.255.0 dip 27 x.x.x.111 x.x.x.115
set interface aggregate1 ext ip x.x.x.1 255.255.255.0 dip 28 x.x.x.116 x.x.x.120
set interface aggregate1 ext ip x.x.x.1 255.255.255.0 dip 25 x.x.x.91 x.x.x.95
Can you please share your advice how to troubleshoot this. Thanks!!