DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
DNS responses are blocked as DoS attacks
- palych
- Topic Author
- Offline
- New Member
Less
More
- Posts: 6
- Thank you received: 0
01 May 2013 10:29 #76015
by palych
DNS responses are blocked as DoS attacks was created by palych
H Everyone
I am experiencing an issue on a Vigor 2850n router, where at some stage it stops passing DNS responses into the network which stops resolving websites on all internal devices and SBS2008 server. Skype and all applications which do not rely on dns are fine.
Mail Alert from Router shows the following:
2013/04/30 17:02:48 -- [DOS][Block][udp_RP_flood, timeout=10][208.67.222.222:53->xxx.xxx.xxx.xxx:36215][UDP][HLen=20, TLen=387]
2013/04/30 17:02:50 -- [DOS][Block][udp_RP_flood, timeout=10][208.67.220.220:53->xxx.xxx.xxx.xxx:55677][UDP][HLen=20, TLen=80]
2013/04/30 17:02:51 -- [DOS][Block][udp_RP_flood, timeout=10][208.67.222.222:53->xxx.xxx.xxx.xxx:36215][UDP][HLen=20, TLen=387]
2013/04/30 17:02:53 -- [DOS][Block][udp_RP_flood, timeout=10][208.67.222.222:53->xxx.xxx.xxx.xxx:59538][UDP][HLen=20, TLen=192]
2013/04/30 17:02:55 -- [DOS][Block][udp_RP_flood, timeout=10][208.67.222.222:53->xxx.xxx.xxx.xxx:37253][UDP][HLen=20, TLen=136]
2013/04/30 17:02:57 -- [DOS][Block][udp_RP_flood, timeout=10][208.67.222.222:53->xxx.xxx.xxx.xxx:51125][UDP][HLen=20, TLen=114]
2013/04/30 17:02:59 -- [DOS][Block][udp_RP_flood, timeout=10][208.67.222.222:53->xxx.xxx.xxx.xxx:64777][UDP][HLen=20, TLen=186]
where xxx.xxx.xxx.xxx is our public IP
obviously i can stop this by stopping DOS protection, which i dont really want to do, so would you recommend something to tackle this issue please
I am experiencing an issue on a Vigor 2850n router, where at some stage it stops passing DNS responses into the network which stops resolving websites on all internal devices and SBS2008 server. Skype and all applications which do not rely on dns are fine.
Mail Alert from Router shows the following:
2013/04/30 17:02:48 -- [DOS][Block][udp_RP_flood, timeout=10][208.67.222.222:53->xxx.xxx.xxx.xxx:36215][UDP][HLen=20, TLen=387]
2013/04/30 17:02:50 -- [DOS][Block][udp_RP_flood, timeout=10][208.67.220.220:53->xxx.xxx.xxx.xxx:55677][UDP][HLen=20, TLen=80]
2013/04/30 17:02:51 -- [DOS][Block][udp_RP_flood, timeout=10][208.67.222.222:53->xxx.xxx.xxx.xxx:36215][UDP][HLen=20, TLen=387]
2013/04/30 17:02:53 -- [DOS][Block][udp_RP_flood, timeout=10][208.67.222.222:53->xxx.xxx.xxx.xxx:59538][UDP][HLen=20, TLen=192]
2013/04/30 17:02:55 -- [DOS][Block][udp_RP_flood, timeout=10][208.67.222.222:53->xxx.xxx.xxx.xxx:37253][UDP][HLen=20, TLen=136]
2013/04/30 17:02:57 -- [DOS][Block][udp_RP_flood, timeout=10][208.67.222.222:53->xxx.xxx.xxx.xxx:51125][UDP][HLen=20, TLen=114]
2013/04/30 17:02:59 -- [DOS][Block][udp_RP_flood, timeout=10][208.67.222.222:53->xxx.xxx.xxx.xxx:64777][UDP][HLen=20, TLen=186]
where xxx.xxx.xxx.xxx is our public IP
obviously i can stop this by stopping DOS protection, which i dont really want to do, so would you recommend something to tackle this issue please
Please Log in or Create an account to join the conversation.
- sicon
- Offline
- Contributor
Less
More
- Posts: 642
- Thank you received: 0
07 May 2013 14:27 #76077
by sicon
Replied by sicon on topic Re: DNS responses are blocked as DoS attacks
Log it with Draytek support.
You could also allow port 53 though the firewall, that should override the DOS defense
You could also allow port 53 though the firewall, that should override the DOS defense
Please Log in or Create an account to join the conversation.
- palych
- Topic Author
- Offline
- New Member
Less
More
- Posts: 6
- Thank you received: 0
12 May 2013 22:27 #76168
by palych
Replied by palych on topic Re: DNS responses are blocked as DoS attacks
Thank you
I have increased threshold and it stopped appearing
I have increased threshold and it stopped appearing
Please Log in or Create an account to join the conversation.
Moderators: Chris, Sami
Copyright © 2024 DrayTek