DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Fraggle Attack

  • pcjazzit
  • Topic Author
  • User
  • User
More
03 May 2023 11:05 #1 by pcjazzit
Fraggle Attack was created by pcjazzit
I appreciate this has been posted before but I think we have a slightly different situation.

Vigor 2927 - Firmware: 4.4.2.3

WAN 1 is connected to a BT Modem router over ethernet
WAN 2 is connected to Fibre Modem router with two Fixed IP's using Alias for the second IP.

Connectivity is all working as expected and we are using bothe WAN 2 IP without issue.

However, we keep getting these Fraggle Attack DoS notofications:

[DOS][Block][fraggle_attack][xxx.xxx.xxx.xxx:5678->255.255.255.255:5678][UDP][HLen=20, TLen=211]

The xxx.xxx.xxx.xxx IP is the gateway address for WAN 2.

The soluton refered to in this post: https://forum.draytek.co.uk/viewtopic.php?p=92864&hilit=fraggle#p92864 Is not appropriate as we do not have a DSL connection. Nor is there an option to disable [System Maintenance] > [Management] > DSL Status - Broadcast to LAN.

This issue started after our ISP added a second IP fixed IP to WAN 2 and installed a Mikrotik fibre modem.

As we have e-mail notifications we are getting bombarded with these Fraggle_attack notices. I could disable the DoS notification, but then that kind defeats the purpose of monitoring for DoS.

Any pointers would be great.

Thanks in advance

Please Log in or Create an account to join the conversation.

  • pcjazzit
  • Topic Author
  • User
  • User
More
03 May 2023 14:47 #2 by pcjazzit
Replied by pcjazzit on topic Re: Fraggle Attack
**Update**
It has been confirmed the Mikrotik was polling the neighbourhood. Similar to the Broadcast to LAN on the Draytek. This has been disabled on the Mikrotik and the Fraggle_attack messgaes have stopped!!. :D

Please Log in or Create an account to join the conversation.