D-Link Forums

The Graveyard - Products No Longer Supported => Routers / COVR => DIR-605L => Topic started by: DilzX on January 09, 2016, 02:38:01 AM

Title: Router under attack ?
Post by: DilzX on January 09, 2016, 02:38:01 AM
Hey guys

I've been having frequent disconnections. Router log shows the following


First Page Last Page Previous Next Page Clear Link To Log Settings
Page 1 of 20

Time and Date   Message
Jan 09 16:06:31   Per-source ACK Flood Attack Detect (ip=216.58.196.110) Packet Dropped
Jan 09 16:06:31   Whole System ACK Flood Attack from WAN Rule:Default deny
Jan 09 16:06:31   Whole System ICMP Flood Attack from WAN Rule:Default deny
Jan 09 16:05:31   Port Scan Attack Detect (ip=216.58.196.101) Packet Dropped
Jan 09 16:05:31   Per-source ACK Flood Attack Detect (ip=216.58.196.101) Packet Dropped
Jan 09 16:05:31   Whole System ACK Flood Attack from WAN Rule:Default deny
Jan 09 16:05:31   Whole System ICMP Flood Attack from WAN Rule:Default deny
Jan 09 16:04:31   Per-source ACK Flood Attack Detect (ip=216.58.220.34) Packet Dropped
Jan 09 16:04:31   Whole System ACK Flood Attack from WAN Rule:Default deny
Jan 09 16:04:04   DHCP lease IP 192.168.0.101 to android-14a806d9d4d2cc22 c0-ee-fb-30-34-02



What does it mean, is it a problem with the router or is it a virus on the PC..? :)
Title: Re: Router under attack ?
Post by: RYAT3 on January 09, 2016, 06:27:11 AM
This ip's look like they are Google

https://www.findip-address.com/216.58.196.101
Title: Re: Router under attack ?
Post by: RYAT3 on January 09, 2016, 06:30:04 AM
You should Google the log messages.

This guy here said it only starts after turning on his laptop.
 
http://security.stackexchange.com/questions/53765/router-detecting-port-scan-and-ack-flood-attack
Title: Re: Router under attack ?
Post by: FurryNutz on January 09, 2016, 09:16:16 AM
Link>Welcome! (http://forums.dlink.com/index.php?topic=48135.0)



Internet Service Provider and Modem Configurations

In most cases its the routers firewall reporting and doing it's job. If your having disconnections due to it, I recommend contacting your ISP service and have them help you with it. Ask for a different WAN IP address coming from the modem. Have them help you monitor the attacks.

Hey guys

I've been having frequent disconnections. Router log shows the following


First Page Last Page Previous Next Page Clear Link To Log Settings
Page 1 of 20

Time and Date   Message
Jan 09 16:06:31   Per-source ACK Flood Attack Detect (ip=216.58.196.110) Packet Dropped
Jan 09 16:06:31   Whole System ACK Flood Attack from WAN Rule:Default deny
Jan 09 16:06:31   Whole System ICMP Flood Attack from WAN Rule:Default deny
Jan 09 16:05:31   Port Scan Attack Detect (ip=216.58.196.101) Packet Dropped
Jan 09 16:05:31   Per-source ACK Flood Attack Detect (ip=216.58.196.101) Packet Dropped
Jan 09 16:05:31   Whole System ACK Flood Attack from WAN Rule:Default deny
Jan 09 16:05:31   Whole System ICMP Flood Attack from WAN Rule:Default deny
Jan 09 16:04:31   Per-source ACK Flood Attack Detect (ip=216.58.220.34) Packet Dropped
Jan 09 16:04:31   Whole System ACK Flood Attack from WAN Rule:Default deny
Jan 09 16:04:04   DHCP lease IP 192.168.0.101 to android-14a806d9d4d2cc22 c0-ee-fb-30-34-02



What does it mean, is it a problem with the router or is it a virus on the PC..? :)