Hello community:
I am having this issue on my router, would this be some kind of flooding? How can I solve this issue, I would appreciate any help please.
Hi Sindy,Why do you consider up to 10 DNS queries per minute a "flood"? Unless this happens even when nothing is connected to the LAN of that router, that's a pretty normal traffic.
So what makes you believe it is unusual?
Thank you MKX.You obfuscated the screenshot a tad too much. But src-mac printed starts with F0:9F:C and if it continues with "2", this means some Ubiquiti in your LAN is actually misbehaving.
And it does look suspicious, requests are highly periodic. Usual usages don't look as periodical.
Any suggestion on what to do would be much appreciated sir.You obfuscated the screenshot a tad too much. But src-mac printed starts with F0:9F:C and if it continues with "2", this means some Ubiquiti in your LAN is actually misbehaving.
And it does look suspicious, requests are highly periodic. Usual usages don't look as periodical.
/export hide-sensitive file=anynameyouwish
plus provide a network diagram.
Today, I got a notification from Barracauda getting blacklisted " LISTED-BARRACUDA-243.202.25x.x6 was listed 900 25"
We added a spammer filter rule to drop spamming.
Thank you anav for taking your time sir. !(1)So all the ethernet ports on the router go to PCs?
(2) why is your IP pool so small??
(3) ether1 doesnt show on your /interface ethernet list??
(4) Assuming you have two wan connections? on etherports 12 & 13?
(5) YOu are missing two important items.
a. /interface list
b. /interface list members
(6) I dont like your firewall rules LOL.
a. get rid of the extra stuff and then determine if you really need it.
b. Stick to the defaults until you understand what each rule does..
c. Notice the SOURCE NAT RULE, replace the one you have with the one below.
d. we can tweak the firewall rules later if necessary............
Yoiu must RESET config from /system reset to give back all default values, if NOTHING are personalized with netinstall or branding.I can erase all rules and start from zero, add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN is not working as on the drop down list it does not show LAN
Thank you rextended. Then I can not do this today, as this router is in service and providing Internet I would have to program it or I can get another RB1100x4 do it offline and then swap. I am currently using RouterOS 6.48.Yoiu must update to latest 6.47.10 and RESET config from /system reset to give back all default values.
Simply copy&paste default firewall rule do not recreate WAN and LAN groups and all other settings.
That's correct rextended =)When you are writing, I have added a link on previous post, read it again
Do not forget to read my previous post:
viewtopic.php?f=2&t=176743&p=866839#p866820
Also Managua, between two Lake and two Ocean, must be really splendid!