Hey everyone
I have got a peculiar problem where the users on routers like Tp-Link, D-link etc are randomly uploading and causing CCR1036 CPU usage to go upto 100% causing packet loss
we have filtered lot of garbage:
- any unknown traffic generated from the network
- any spoof traffic coming into the network
- any DNS request coming from WAN
- any UDP packet coming from WAN
- any new TCP request coming from WAN
- any traffic from PPP going to PPP
- any traffic to access TCP port 20-23 from PPPoE (getting almost 10,000pps)
- ALL Invalid Packets
- ALL ICMP coming from WAN
still, there is a random upload that generates for 1~3 seconds from all the 500+ routers.
the only problem I think could effect is that the administrator before me had several IP addresses on PPPoE interface to serve static IP customers and that could be causing the havoc but for last 7~8 months the configuration is the same and nothing much has changed this problem started 3 days back.
All information/suggestion will be welcomed
Thanks