• April 18, 2024, 08:03:12 AM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: Router under attack ?  (Read 8370 times)

DilzX

  • Level 1 Member
  • *
  • Posts: 1
Router under attack ?
« on: January 09, 2016, 02:38:01 AM »

Hey guys

I've been having frequent disconnections. Router log shows the following


First Page Last Page Previous Next Page Clear Link To Log Settings
Page 1 of 20

Time and Date   Message
Jan 09 16:06:31   Per-source ACK Flood Attack Detect (ip=216.58.196.110) Packet Dropped
Jan 09 16:06:31   Whole System ACK Flood Attack from WAN Rule:Default deny
Jan 09 16:06:31   Whole System ICMP Flood Attack from WAN Rule:Default deny
Jan 09 16:05:31   Port Scan Attack Detect (ip=216.58.196.101) Packet Dropped
Jan 09 16:05:31   Per-source ACK Flood Attack Detect (ip=216.58.196.101) Packet Dropped
Jan 09 16:05:31   Whole System ACK Flood Attack from WAN Rule:Default deny
Jan 09 16:05:31   Whole System ICMP Flood Attack from WAN Rule:Default deny
Jan 09 16:04:31   Per-source ACK Flood Attack Detect (ip=216.58.220.34) Packet Dropped
Jan 09 16:04:31   Whole System ACK Flood Attack from WAN Rule:Default deny
Jan 09 16:04:04   DHCP lease IP 192.168.0.101 to android-14a806d9d4d2cc22 c0-ee-fb-30-34-02



What does it mean, is it a problem with the router or is it a virus on the PC..? :)
Logged

RYAT3

  • Level 10 Member
  • *****
  • Posts: 2254
Re: Router under attack ?
« Reply #1 on: January 09, 2016, 06:27:11 AM »

This ip's look like they are Google

https://www.findip-address.com/216.58.196.101
Logged

RYAT3

  • Level 10 Member
  • *****
  • Posts: 2254
Re: Router under attack ?
« Reply #2 on: January 09, 2016, 06:30:04 AM »

You should Google the log messages.

This guy here said it only starts after turning on his laptop.
 
http://security.stackexchange.com/questions/53765/router-detecting-port-scan-and-ack-flood-attack
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Router under attack ?
« Reply #3 on: January 09, 2016, 09:16:16 AM »

Link>Welcome!

  • What Hardware version is your router? Look at sticker under the router case.
  • Link>What Firmware version is currently loaded? Found on the routers web page under status.
  • What region are you located?


Internet Service Provider and Modem Configurations
  • What ISP Service do you have? Cable or DSL?
  • What ISP Modem Mfr. and model # do you have?

In most cases its the routers firewall reporting and doing it's job. If your having disconnections due to it, I recommend contacting your ISP service and have them help you with it. Ask for a different WAN IP address coming from the modem. Have them help you monitor the attacks.

Hey guys

I've been having frequent disconnections. Router log shows the following


First Page Last Page Previous Next Page Clear Link To Log Settings
Page 1 of 20

Time and Date   Message
Jan 09 16:06:31   Per-source ACK Flood Attack Detect (ip=216.58.196.110) Packet Dropped
Jan 09 16:06:31   Whole System ACK Flood Attack from WAN Rule:Default deny
Jan 09 16:06:31   Whole System ICMP Flood Attack from WAN Rule:Default deny
Jan 09 16:05:31   Port Scan Attack Detect (ip=216.58.196.101) Packet Dropped
Jan 09 16:05:31   Per-source ACK Flood Attack Detect (ip=216.58.196.101) Packet Dropped
Jan 09 16:05:31   Whole System ACK Flood Attack from WAN Rule:Default deny
Jan 09 16:05:31   Whole System ICMP Flood Attack from WAN Rule:Default deny
Jan 09 16:04:31   Per-source ACK Flood Attack Detect (ip=216.58.220.34) Packet Dropped
Jan 09 16:04:31   Whole System ACK Flood Attack from WAN Rule:Default deny
Jan 09 16:04:04   DHCP lease IP 192.168.0.101 to android-14a806d9d4d2cc22 c0-ee-fb-30-34-02



What does it mean, is it a problem with the router or is it a virus on the PC..? :)
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.