User comments on ISPs
  >> Zen Internet


Register (or login) on our website and you will not see this ad.


These posts have been archived and can no longer be replied to or modified.
  Print Thread
Standard User deleted
(deleted) Wed 08-Nov-06 21:00:12
Print Post

DoS attack or line fault?


[link to this post]
 
Hi All,

I've been having intermittant disconnects for the last week or so and I can't work out if it's down to a bad line or because I'm sufferring a DoS attack. Up until now my line has been remarkably stable - It's the old 2M home service.

The symptoms are that I simply lose internet access - web pages time out. The router usually thinks the line is still up but eventually it drops for 10-20 seconds then comes back on it's own. Access is then OK for a while.

My first guess was that BT were having exchange problems and i see from the forums a few other zen customers have had that problem recently. The SNR stats look OK though, 13.5dB downstream, 15dB up.

I have also noticed a whole load of traffic in my logs that I can't explain - hundreds of hits from various IP addresses all targetting my router on port 40097. I have a /29 network but only the router is being targetted - not the other hosts. The router is a Cisco 837 and I haven't been able to find any info about this activity. It is being dropped it but I guess the router still has to process it. Is anyone else seeing anything like this?

e.g.
Nov 8 20:50:08: %SEC-6-IPACCESSLOGP: list 100 denied tcp 90.227.204.100(2315) -> my.ip.add.ress(40097), 1 packet
Nov 8 20:50:14: %SEC-6-IPACCESSLOGP: list 100 denied tcp 82.73.24.147(3798) -> my.ip.add.ress(40097), 1 packet
Nov 8 20:50:17: %SEC-6-IPACCESSLOGP: list 100 denied tcp 200.30.163.211(43379) -> my.ip.add.ress(40097), 1 packet

Standard User LG_ukM
(experienced) Wed 08-Nov-06 21:43:29
Print Post

Re: DoS attack or line fault?


[re: deleted] [link to this post]
 
I'm pretty sure a DDOS attack wouldn't cause disconnects unless they were able to completely crash your router, which I doubt as it's designed to take that level of sustained traffic (especially being Cisco kit)

|ZeN 2Mb/s | 8 IP's | ST 510v4 | 241.6kb (d) 30.3kb (u)
PlayZeN.net www.zenclan.org.uk
Standard User deleted
(deleted) Wed 08-Nov-06 21:58:02
Print Post

Re: DoS attack or line fault?


[re: deleted] [link to this post]
 
It's much more likely to be background noise. I get log entries like that all the time.

Easy way to be sure though, look at the output from 'show processes cpu sorted 5sec' - the top line should be something like "CPU utilization for five seconds: 6%/1%; one minute: 5%; five minutes: 5%". If the values are near or at 100%, you might have a problem.

In reply to:

The router usually thinks the line is still up but eventually it drops for 10-20 seconds then comes back on it's own




So it loses sync? Unlikely to be a DoS then.

Though my old 837 had a habit of losing sync but thinking it was still synched up (and the ADSL bits locking up in the process)...


Register (or login) on our website and you will not see this ad.

  Print Thread

Jump to