Hi,
For the past few days, we say huge incoming traffic on our wan port. Figured out some random IPs from trying to connect to port 80 of some random lan IP. Lan IP is not configured anywhere. We saw 100% CPU load so added a raw filter to drop such connections. Now CPU sits normal but wan port 100% used.
One such connection
prerouting: in:vlan1018-Airtel-ILL out:(unknown 0), src-mac c2:bf:a7:96:fe:35, proto UDP, 5.104.160.88:53->LanpublicIP:80, prio 3->0, len 1476
Added blackhole route too but it's not helping. No service is running on LAN side on port 80.
Adding ruled to ip firewall filter is not lowering the CPU.
Any suggestions on mitigation the issue?