Checking unknown source of traffic

Hi all,

I’ve noticed something strange on my interfaces with the amount of traffic passing through ether1 and ether2. Please see images below.
Ether1 is configured with the ISP settings and ether2 is configured with 1 private IP address which I have queued.
From experience, ether1 Rx and ether2 Tx usually have almost about the same traffic. I need to check where the extra traffic is coming from and how to block it.
Mikrotik Traffic.jpg

You could use Tools->Torch to see what is happening on your interface…

Hi, I’ve been able to see the unwanted traffic on the ether1 interface. How do I now drop this traffic so that is stops consuming my bandwidth?

if the traffic reaches your interface - you cannot stop it, it’s already there. you need to drop it somewhere at the source point

Hi Experts,

I face exactly the same issue on one of my routers and it looks like I am receiving traffic from an unknown sources to the Interface that has the Public IP of the router. Is that a kind of traffic flood attack? Is there any possible way to block them? I face this issue from time to time and I usually change the Public IP that I am using for my router to solve the problem. Any possible way to report these IPs?

Ammar.