Community discussions

MikroTik App
 
baracudas
just joined
Topic Author
Posts: 9
Joined: Tue Sep 10, 2013 11:02 am

dns connection issue

Thu Oct 10, 2013 12:22 pm

i use 2.9.27 version and i am recentrly facing some issues.
i see cpu 100% and when i run torch, one of my wan interfaces shows too many connections from 2 specific ips and different ports to local 53 port.

After i drop input of those 2 ips, in torch i see the same behaviour.
I have disabled remote dns requests but not fixed.

here is a screenshot of torch.
You do not have the required permissions to view the files attached to this post.
 
Rudios
Forum Veteran
Forum Veteran
Posts: 966
Joined: Mon Mar 11, 2013 12:58 pm
Location: The Netherlands

Re: dns connection issue

Thu Oct 10, 2013 2:02 pm

I think torch shows the packets because the are send to you.
It is regardless of what the firewall does with the received packages.
I assume you are being used as an DNS relay.
Post your ip firewall filter output so we can assist you in blocking unwanted traffic
Testing setup with: 2 x RB750UP | 2 x RB750GL | 1 x RB951G-2HnD | 1 x RB2011UiAS-IN
 
User avatar
janisk
MikroTik Support
MikroTik Support
Posts: 6284
Joined: Tue Feb 14, 2006 9:46 am
Location: Riga, Latvia

Re: dns connection issue

Thu Oct 10, 2013 2:10 pm

there is no reason to use such an old version. Update to newer.
 
baracudas
just joined
Topic Author
Posts: 9
Joined: Tue Sep 10, 2013 11:02 am

Re: dns connection issue

Thu Oct 10, 2013 7:04 pm

I think torch shows the packets because the are send to you.
It is regardless of what the firewall does with the received packages.
I assume you are being used as an DNS relay.
Post your ip firewall filter output so we can assist you in blocking unwanted traffic
Here is ip firewall filter output.
You do not have the required permissions to view the files attached to this post.
 
deejayq
Member Candidate
Member Candidate
Posts: 195
Joined: Wed Feb 23, 2011 8:33 am

Re: dns connection issue

Fri Oct 11, 2013 6:18 pm

had a similar experience
seemed some sort of a dos
just block the two ip's and you should be fine.
 
baracudas
just joined
Topic Author
Posts: 9
Joined: Tue Sep 10, 2013 11:02 am

Re: dns connection issue

Sat Oct 12, 2013 1:38 pm

had a similar experience
seemed some sort of a dos
just block the two ip's and you should be fine.

It's odd but i i drop those ip's but the problem persist. Beside that, every day i have some other ip.attacking.

Who is online

Users browsing this forum: Baidu [Spider] and 52 guests