Community discussions

MikroTik App
 
helectro
newbie
Topic Author
Posts: 46
Joined: Mon Jun 28, 2010 1:09 am

excessive traffic, can't block it!

Mon Jun 28, 2010 1:33 am

Hi guys, appreciate any hint

I have an incoming traffic to the public IP address of Mt I could not block

I put a quee to the source IP address 89.28.59.104 and 4 put firewall rules in the input and output foward even I have
2,5 Megas in RX from this ip with many packages of 122bps PD inbound ip ping response

i put this Firewall filter rules:
;;; Bomabrdero Trafico Extra o
chain=input action=drop src-address=89.28.59.104 packet-size=0

1 ;;; Bombandero Extra o
chain=forward action=drop protocol=udp src-port=32916

2 ;;; Bombandero Extra o
chain=forward action=drop protocol=udp src-port=51777

3 ;;; Drop Trafico Extra o
chain=forward action=drop src-address=89.28.59.104

4 ;;; Bomabrdero Trafico Extra o
chain=virus action=drop dst-address=89.28.59.104

The routerboard is RB450G with 3.30
You do not have the required permissions to view the files attached to this post.
 
bafh
Frequent Visitor
Frequent Visitor
Posts: 83
Joined: Sun Jun 27, 2010 3:59 pm
Location: Libau, Lettland

Re: excessive traffic, can't block it!

Mon Jun 28, 2010 7:48 pm

What is the point of dropping src-ports?
Judging by the country (Moldova), that is a torrent or a botnet. Just drop that IP (all protocols) in firewall and thats all. No shapes no useless CPU usage. I don't see a problem.
 
helectro
newbie
Topic Author
Posts: 46
Joined: Mon Jun 28, 2010 1:09 am

Re: excessive traffic, can't block it!

Tue Jun 29, 2010 2:27 am

bafh appreciate the help and had tried that but it did not work with continuous traffic from that ip to the wan of my MT I have not managed to block traffic in Rx and before applying these rules and the cpu was at 100% I had to disconnect the cable port to prove, with several rules including Mt try another router to verify that no port would be a problem when you connect the cable in the wan immediately see rx TORCH to the interface wan and the 3000 lines from this ip address to 0 Bps but which together consume almost 3Mbps

PS sorry for my poor English
 
bafh
Frequent Visitor
Frequent Visitor
Posts: 83
Joined: Sun Jun 27, 2010 3:59 pm
Location: Libau, Lettland

Re: excessive traffic, can't block it!

Tue Jun 29, 2010 9:10 am

You are simply doing something wrong. RTFM about droping by src IP and thats all. Erase the rules and add them again, remember - order counts too 8)
And there is a small possibility that upgrading to 4.xx version would help and a tiny possibility (usually with wireless involved) that resetting the config and writing it new will help.
Have experienced such with... don't remember the version anymore so it must be before 3.xx

Who is online

Users browsing this forum: Amazon [Bot], qatar2022, vagrik and 210 guests