Sorry, that would be mine. I'm building a new gateway and was having some issues, I'll disable that host asap. Josh - VK2HFF
-------- Original message -------- From: lleachii--- via 44Net 44net@hamradio.ucsd.edu Date: 28/06/2017 05:03 (GMT+10:00) To: 44net@hamradio.ucsd.edu Cc: lleachii@aol.com Subject: Re: [44net] SYN Flood, etc.
Rob,
It appears the SYN Flood are actually coming from AMPPRNet, not the Interent:
2017-06-27 13:16:16.705 3600.001 TCP 44.136.24.62:52055 -> 44.60.44.3:53 9 695 1 2017-06-27 13:16:16.705 3600.001 TCP 44.60.44.3:53 -> 44.136.24.62:52055 41 49452 1
2017-06-27 13:18:41.842 3600.004 TCP 44.136.24.62:51655 -> 44.60.44.3:53 4 306 1 2017-06-27 13:18:41.842 3600.004 TCP 44.60.44.3:53 -> 44.136.24.62:51655 28 37152 1
After closing tcp/53, this is the only host causing hits on my SYN Flood filter.
- KB3VWG
_________________________________________ 44Net mailing list 44Net@hamradio.ucsd.edu http://hamradio.ucsd.edu/mailman/listinfo/44net