cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

356
Views
0
Helpful
0
Replies
steve
Beginner

How to resume after SYN FLOOD with a RV180

I have a new RV180 and Monday I had a SYN FLOOD from one location. They have corrected the problem, but they still can't connect or ping the one IP address they send the SYN FLOOD on. They can however connect to all the other IP addresses configured on the RV180. Is there something in the RV180 that is continuing to block them?

The RV180 is setup as a gateway. The main IP address is using port forwarding and the reset of the IP addresses are using One-to-One NAT with a range. The IP address that is blocked is in the middle of the One-to-One NAT range. The destination server is running Serve 2008 R2.

Here is the line from the log when the attack started:

Tue Nov 13 04:03:37 2012(GMT-0600) [rv180][Kernel][KERNEL] [262504.820000] SYNFLOODIN=eth1 OUT=bdg1 SRC=xxx.xxx.xxx.xxx DST=192.168.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=8780 DF PROTO=TCP SPT=2785 DPT=80 WINDOW=65535 RES=0x00 SYN URGP=0

Here they are coming into the working IP address today:

[rv180]Thu Nov 15 10:01:19 2012(GMT-0600) [rv180][Kernel][KERNEL] [456767.100000] WAN_LAN[ACCEPT]IN=eth1 OUT=bdg1 SRC= xxx.xxx.xxx.xxx DST=192.168.xxx.xxx LEN=52 TOS=0x00 PREC=0x00 TTL=110 ID=22909 DF PROTO=TCP SPT=50765 DPT=80 WINDOW=8192 RES=0x00 SYN URGP=0

0 REPLIES 0