Hello All,
I have a lot of unidentified outgoing traffic from my WAN. They are not reaching any of my servers or users just from Tx of my WAN port.
Please help.
Thank you.
Hello All,
I have a lot of unidentified outgoing traffic from my WAN. They are not reaching any of my servers or users just from Tx of my WAN port.
Please help.
Thank you.
Hi,
Did you torch and check what kind of traffic is leaving the wan interface?
Yes… Its to some german servers and alibaba servers.
None of this traffic with high Tx is coming from my users. My LAN Rx is way less compared to my WAN Tx.
What I mean is: There is a lot of upload from my WAN and this is not from any of my users.
Aren’t you part of dns amplification attack? Hope your dns service is not accessible from the wan…
I am sure it was the attack. I added basic firewall rules and its fine now. Phew..
Thank for the help.
Watch out. If you were allowing port 53 from outside and disabled it by rule, what about the other communication? You need to rethink your firewalling approach to be safe.