DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

2830 DoS udp flood

More
27 Jul 2011 09:05 #68762 by dziki
2830 DoS udp flood was created by dziki
I have an issue with my 2830. For some reason I keep getting loads of DoS udp flood attacks to the point that I cannot reach any websites.

1292011-07-27 08:33:02Jul 27 08:32:27Home[DOS][Block][udp_RP_flood, timeout=900][94.245.121.251:3544->195.200.30.11:62741][UDP][HLen=20, TLen=84]
1292011-07-27 08:33:09Jul 27 08:32:34Home[DOS][Block][udp_RP_flood, timeout=900][94.245.121.251:3544->195.200.30.11:62741][UDP][HLen=20, TLen=84]
1292011-07-27 08:33:11Jul 27 08:32:36Home[DOS][Block][udp_RP_flood, timeout=900][80.0.166.219:54824->195.200.30.11:62741][UDP][HLen=20, TLen=80]
1292011-07-27 08:33:12Jul 27 08:32:37Home[DOS][Block][udp_RP_flood, timeout=900][87.194.255.154:53->195.200.30.11:3631][UDP][HLen=20, TLen=106]
1292011-07-27 08:33:17Jul 27 08:32:41Home[DOS][Block][udp_RP_flood, timeout=900][195.182.193.235:100->195.200.30.11:49586][UDP][HLen=20, TLen=131]
1292011-07-27 08:33:25Jul 27 08:32:50Home[DOS][Block][udp_RP_flood, timeout=900][183.83.132.194:30227->195.200.30.11:49586][UDP][HLen=20, TLen=131]
1292011-07-27 08:33:31Jul 27 08:32:55Home[DOS][Block][udp_RP_flood, timeout=900][87.194.255.154:53->195.200.30.11:3833][UDP][HLen=20, TLen=106]
1292011-07-27 08:33:49Jul 27 08:33:13Home[DOS][Block][udp_RP_flood, timeout=900][87.194.255.154:53->195.200.30.11:3774][UDP][HLen=20, TLen=106]
1292011-07-27 08:33:53Jul 27 08:33:17Home[DOS][Block][udp_RP_flood, timeout=900][121.45.154.115:46806->195.200.30.11:32904][UDP][HLen=20, TLen=58]
1292011-07-27 08:33:53Jul 27 08:33:17Home[DOS][Block][udp_RP_flood, timeout=900][87.194.255.154:53->195.200.30.11:62644][UDP][HLen=20, TLen=76]
1292011-07-27 08:33:56Jul 27 08:33:20Home[DOS][Block][udp_RP_flood, timeout=900][121.45.154.115:46806->195.200.30.11:32904][UDP][HLen=20, TLen=58]
1292011-07-27 08:33:57Jul 27 08:33:21Home[DOS][Block][udp_RP_flood, timeout=900][72.89.110.138:52193->195.200.30.11:32904][UDP][HLen=20, TLen=96]
1292011-07-27 08:33:59Jul 27 08:33:23Home[DOS][Block][udp_RP_flood, timeout=900][87.194.255.154:53->195.200.30.11:56453][UDP][HLen=20, TLen=76]

The only thing what I can do is to reboot the router and then it's working for some time... I have increased timeout from default 10 to 900 but this have no effect. Anyone had similar issues?

Please Log in or Create an account to join the conversation.

More
27 Jul 2011 11:34 #68767 by voodle
Replied by voodle on topic Re: 2830 DoS udp flood
The UDP flood defense is actually quite a simple system and will trigger if it goes over the number of UDP packets per second which is 150 by default I think. UDP is used by games, VPNs and DNS, which means when the UDP flood defense gets triggered, you have no DNS :)
By setting the timeout to 900 you've probably made it worse - that's mostly normal internet traffic being sent back to your PC and looking at the ports it appears to be outbound for instance this one: 87.194.255.154:53->195.200.30.11:62644 is a PC sending a DNS query to 87.194.255.154 and it's been counted as a DoS attack.

You can fix it by upping the threshold or disabling UDP flood control altogether.

Please Log in or Create an account to join the conversation.

More
27 Jul 2011 21:09 #68791 by dziki
Replied by dziki on topic Re: 2830 DoS udp flood
Thanks for the answer I had discovered at the end that DNS from my ISP is playing up and what I took for DoS attacks was as you said DNS query. Probobaly my ISP have some issues with the DNS...

Please Log in or Create an account to join the conversation.

Moderators: Sami