I been using my RB1100AHx2 since 2016 and never been have this problem until this past few weeks.
I notice that there is still an activity even i disabled all of my out interfaces. I have 4 active port as follow:
ETH1 — WAN1 (100mb)
ETH2 — WAN2 (2mb)
ETH9 — LAN OUT
ETH10 — VLAN OUT (VLAN 40 ,99, 100)
I tried to disable both ETH 9 and 10 and leave only ETH 1 & 2 which are both IN-interface. On this case no one uses either of the 2 ISP but still have TX activity.
I also check this activity using torch and see some of IP are using my internet. How this happen? is this even possible?
Hello,
I think your router is most likely being used as an “attack bot” against other networks.
Check if you have open DNS, Proxy, FTP or NTP services or ports on your router.
Also, when using “Torch tool” you can see type of the traffic by selecting “Port” and “Protocol” before clicking on the start button.
This can be extremely helpfull in troubleshooting.
Do you mean IP>services?
i only enable winbox and www
by the way this event started a week after i setup PPTP-vpn in my router.
Also for updates as of dec 19, 2019, i temporarily disabled PPTP and changed my RB ip aswell.
but we need this PPTP-vpn for our main and remote office.
Found this “Dos-attacked tutorial” in some thread and try this Filter rule as :
IP/Firewall
Add Filter Rule.
Chain=input
DST Address (Your Public IP)
Protocol UDP
DSP Port 53
Action Drop
after enabling that filter rule i see this in my log
Do you know what this mean?
The recommendations from that page should be enough to protect your router against the most common attacks.
Be careful not to lock yourself out of the router in that process.
So be sure that you understand what exactly each command (and firewall rule) does before you type it into the router’s terminal.
However, if someone did hack your router then some additional steps might be necessary.
UDP port 53 is used by DNS service and can be exploited in an amplification type attack.