DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
udp_flood mesages
- robingb
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 10
- Thank you received: 0
17 Jul 2009 09:37 #56760
by robingb
udp_flood mesages was created by robingb
I have just started using my 2820vn but get between 3 and 5 "Mail alert from Router" emails a day all with the same type of message in them, e.g....
[DOS][Block][udp_flood, timeout=10][86.133.242.41:4500->86.133.242.41:62590][UDP][HLen=20, TLen=1376]
[DOS][Block][udp_flood, timeout=10][86.133.242.41:4500->86.133.242.41:62590][UDP][HLen=20, TLen=1376]
[DOS][Block][udp_flood, timeout=10][86.133.242.41:4500->86.133.242.41:62590][UDP][HLen=20, TLen=1376]
[DOS][Block][udp_flood, timeout=10][86.133.242.41:4500->86.133.242.41:62590][UDP][HLen=20, TLen=1376]
[DOS][Block][trace_route][86.133.242.41:12378->86.133.242.41:33436][UDP][HLen=20, TLen=32]
[DOS][Block][trace_route][86.133.242.41:12378->86.133.242.41:33436][UDP][HLen=20, TLen=32]
[DOS][Block][udp_flood, timeout=10][86.133.242.41:4500->86.133.242.41:62312][UDP][HLen=20, TLen=1376]
[DOS][Block][udp_flood, timeout=10][86.133.242.41:4500->86.133.242.41:62648][UDP][HLen=20, TLen=128]
[DOS][Block][udp_flood, timeout=10][86.133.242.41:4500->86.133.242.41:62648][UDP][HLen=20, TLen=912]
Where 86.133.242.41 is my WAN IP address. If I understand the log correctly it shows my Routers WAN interface is probing itself?
If anyone can help me understand this I would be gratefull. I searched the forum for "udp_flood" but it seems I am the only one where the IP is the same on both sides of the "->".
Thanks
RobinGB
[DOS][Block][udp_flood, timeout=10][86.133.242.41:4500->86.133.242.41:62590][UDP][HLen=20, TLen=1376]
[DOS][Block][udp_flood, timeout=10][86.133.242.41:4500->86.133.242.41:62590][UDP][HLen=20, TLen=1376]
[DOS][Block][udp_flood, timeout=10][86.133.242.41:4500->86.133.242.41:62590][UDP][HLen=20, TLen=1376]
[DOS][Block][udp_flood, timeout=10][86.133.242.41:4500->86.133.242.41:62590][UDP][HLen=20, TLen=1376]
[DOS][Block][trace_route][86.133.242.41:12378->86.133.242.41:33436][UDP][HLen=20, TLen=32]
[DOS][Block][trace_route][86.133.242.41:12378->86.133.242.41:33436][UDP][HLen=20, TLen=32]
[DOS][Block][udp_flood, timeout=10][86.133.242.41:4500->86.133.242.41:62312][UDP][HLen=20, TLen=1376]
[DOS][Block][udp_flood, timeout=10][86.133.242.41:4500->86.133.242.41:62648][UDP][HLen=20, TLen=128]
[DOS][Block][udp_flood, timeout=10][86.133.242.41:4500->86.133.242.41:62648][UDP][HLen=20, TLen=912]
Where 86.133.242.41 is my WAN IP address. If I understand the log correctly it shows my Routers WAN interface is probing itself?
If anyone can help me understand this I would be gratefull. I searched the forum for "udp_flood" but it seems I am the only one where the IP is the same on both sides of the "->".
Thanks
RobinGB
Please Log in or Create an account to join the conversation.
- busta999
- Offline
- Junior Member
Less
More
- Posts: 49
- Thank you received: 0
07 Aug 2009 13:45 #57070
by busta999
Replied by busta999 on topic udp_flood mesages
Are you running a VPN through the router?
I ran into the same issue that was causing mayhem with my corporate VPN connection.
Then I found a post that talked about the router misinterpretting the VPN traffic as a udp_flood attack.
As soon as I turned off the DOS protection against udp_flood the VPN worked again and I stopped getting all the error messages.
Hope that helps.
I ran into the same issue that was causing mayhem with my corporate VPN connection.
Then I found a post that talked about the router misinterpretting the VPN traffic as a udp_flood attack.
As soon as I turned off the DOS protection against udp_flood the VPN worked again and I stopped getting all the error messages.
Hope that helps.
Please Log in or Create an account to join the conversation.
- mawallace
- Offline
- Junior Member
Less
More
- Posts: 26
- Thank you received: 0
07 Aug 2009 14:54 #57071
by mawallace
Replied by mawallace on topic udp_flood mesages
Same thing here! I had an issue where the VPN kept dropping at random intervals - when I inspected the logs it was the same sort of message you were getting
i tuned off udp flood attack and no issues (yet!)
i tuned off udp flood attack and no issues (yet!)
Please Log in or Create an account to join the conversation.
Moderators: Chris, Sami
Copyright © 2024 DrayTek