Community discussions

MikroTik App
 
whiskeyman7
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 86
Joined: Tue Jul 30, 2013 8:30 pm
Location: Costa Rica

Unknown ICMP traffic from wan port.

Thu Nov 14, 2013 9:44 pm

Hello All,

We have an rb1200 v5.26.

My company has have been under constant attack for the last week and we have been successful in identifying and blocking the offending ip's. But recently we have noticed about 330-200 KB's of ICMP traffic being transmitted from our Wan port to some chinese IP.

I torched all other lan ports and found only a couple of bytes of ICMP traffic, all local ICMP traffic did not add up to what we see on wan.

So, it would seem that the ICMP traffic is originating from our router.

My question is this. How is this possible and how can we stop it?

Thanks in advance....
 
CelticComms
Forum Guru
Forum Guru
Posts: 1765
Joined: Wed May 02, 2012 5:48 am

Re: Unknown ICMP traffic from wan port.

Thu Nov 14, 2013 10:05 pm

It is not uncommon for people to misinterpret what they see in Torch so firstly I would double check the direction.
Secondly, make sure nobody else left ping running on the router.... ;)

If you are still left with a worry and want another pair of eyes to look at it drop me an email. There may may be a simple explanation. China does seem to spend a large part of its time probing IP numbers...
 
whiskeyman7
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 86
Joined: Tue Jul 30, 2013 8:30 pm
Location: Costa Rica

Re: Unknown ICMP traffic from wan port.

Thu Nov 14, 2013 10:41 pm

Thank you for the reply,

I triple checked and found no one running pings.

Here is a screenshot.

Image
 
CelticComms
Forum Guru
Forum Guru
Posts: 1765
Joined: Wed May 02, 2012 5:48 am

Re: Unknown ICMP traffic from wan port.

Thu Nov 14, 2013 10:59 pm

Have you checked what other traffic there is involving that host? If you sniff some of the traffic into a pcap file Wireshark can give a lot more info in the nature of the ICMP traffic.
 
whiskeyman7
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 86
Joined: Tue Jul 30, 2013 8:30 pm
Location: Costa Rica

Re: Unknown ICMP traffic from wan port.

Fri Nov 15, 2013 1:44 am

Thank you for the reply.

I ended up just blocking the the who subnet of the offending attacker and the icmp traffic stopped.

Who is online

Users browsing this forum: No registered users and 60 guests