cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
1,078 Views
Message 1 of 11

DoS(SYN Flooding) Normal to see in the Event Log?

Been having some weird internet problems, just curious if that's normal to see

0 Ratings
Reply
10 REPLIES 10
1,048 Views
Message 2 of 11

Re: DoS(SYN Flooding) Normal to see in the Event Log?

Perfectly normal, just your firewall doing it's job.

0 Ratings
Reply
1,022 Views
Message 3 of 11

Re: DoS(SYN Flooding) Normal to see in the Event Log?

Weird that you say that because I just gone done chatting with BT, and they said it's not normal.  He tested my line and claimed to have fixed the problem. Maybe it was something else that was affecting my internet but I did specifically ask him if DoS(SYN Flooding) is normal and he said it's not. 

0 Ratings
Reply
1,011 Views
Message 4 of 11

Re: DoS(SYN Flooding) Normal to see in the Event Log?

It's not "normal" but sadly, it is routine today.  Don't know why he said he fixed it though.  It's not something he can fix unless BT's own systems are throwing a wobbley.

0 Ratings
Reply
1,005 Views
Message 5 of 11

Re: DoS(SYN Flooding) Normal to see in the Event Log?

Yeah I just tested playing some games, It's for sure not fixed. It's just weird because I had my router replaced the problem was fixed for a month or so, my internet speed is good, it's just sometimes when i'm playing games i have trouble connecting to servers. Driving me crazy lol

0 Ratings
Reply
941 Views
Message 6 of 11

Re: DoS(SYN Flooding) Normal to see in the Event Log?

Sadly the BT 'guides' aren't technical and their information cannot be relied upon.

0 Ratings
Reply
905 Views
Message 7 of 11

Re: DoS(SYN Flooding) Normal to see in the Event Log?

Ah well, Not sure what I can even do at this point then. 

0 Ratings
Reply
794 Views
Message 8 of 11

Re: DoS(SYN Flooding) Normal to see in the Event Log?

DoS attacks are based on the WAN IP address.  So the easy fix is usually to force the WAN IP to change by rebooting or powering down the router (and possibly ONT) for a few minutes.  Once you no longer have this WAN IP you should see a let up in the DoS attacks, and unfortunately some other poor soul will *probably inherit the problem.

*Probably, because if the issue is caused by a compromised device on your network advertising itself to a would-be attacker, it'll restart pretty sharpish.  It's unlikely to be the case, but is possible, so don't fixate on that possibility!


I only learn by making mistakes and owning up to them - boy do I learn a lot!
0 Ratings
Reply
779 Views
Message 9 of 11

Re: DoS(SYN Flooding) Normal to see in the Event Log?

It might be a flaw in the SH2 itself.

I have two SH2’s.  For no obvious reason, one started doing CWMP sessions once an hour and spoofing, scanning, syn floods etc. dropped to virtually nothing.  The other persists in CWMP once a day and lots of scanning, spoofing etc.

Just coincidence?

0 Ratings
Reply
768 Views
Message 10 of 11

Re: DoS(SYN Flooding) Normal to see in the Event Log?

I use a third-party router.  If I enable a more complex firewall, I can log every attempted attack.  There are far more simple attacks on IP addresses than most people realise.  Until it starts causing problems, it's just something you have to live with!


I only learn by making mistakes and owning up to them - boy do I learn a lot!
0 Ratings
Reply