Community discussions

MikroTik App
 
msatter
Forum Guru
Forum Guru
Topic Author
Posts: 2912
Joined: Tue Feb 18, 2014 12:56 am
Location: Netherlands / Nīderlande

Detect Internet triggering flood of incoming connections

Mon Nov 12, 2018 11:31 am

I made a posting yesterday about my LOG being flooded by incoming connections from Google DNS ( 8.8.8.8 ) and thanks to mkx I could stop that by disabling the option Detect Internet under interfaces in the Mikrotik router.

viewtopic.php?f=2&t=141454

It looked like an attack, every second a connection came in on port 5768 and that is rather specific for Mikrotik routers. So this morning I started WireShark to see on what port Detect Internet was using to contact Google. Yes you guessed it, it was port 5768.
Detectinternet.JPG
I think that it would be better to use random outgoing ports for Detect Internet.

I can't block the Detect Internet requests but the RAW rules will see the fall-out of Detect Internet.
You do not have the required permissions to view the files attached to this post.

Who is online

Users browsing this forum: GoogleOther [Bot] and 159 guests