D-Link DIR-655 :: Detect / Stop DDOS Attacks With It?
Mar 22, 2013
i can detect the IP of DDOS attacks and if there's a simple way to prevent it. I've heard different suggestions from blocking incoming ping requests to blocking specific IP ranges
I am wondering how to change my internet IP address as someone is DDOS attacking me on a daily basis. I have tried all the ipconfig stuff, and unplugged my modem for an hour. Not sure what to do at this point. Plugging my PC directly to the modem changes my IP, but then when I plug my PC back into my router, it changes back.
I am currently getting DoS/DDoS on my asa 5520 , the attacker is hitting IP's that are not even open on any port. The attack is filling up the queues on the firewall which is at 99% CPU during the attack. here's the NetFlow info that I was able to get from my ISP ( since I dont have a Router to do that ). [code]
Is there anyway to block a DDOS attack? I dont know to much about DDOS attacks and how they work, but i think i understand a little bit of it. Is there no way to configure a firewall to detect rapid, spontaneous,continuous amounts of fragmented, random data coming from an IP address? Wouldn't the data coming in from a DDOS server be somewhat distinct from data that flows normally
I've noticed in the mornings lately when I get up around 6 am my internet will not work. Not on wireless or on my desktop. I decided I'd log into the router to see if there was a firmware update or anything. I had checked the logs and there are quite a few entries relating to DoS. I googled around and saw that it could be some sort of packet loss and the router is mistaking it for some sort of DoS attack. And that due to it not showing up multiple times every second it likely isn't a DoS attack. Here is a few from the logs:
Does Cisco ASA5510 or 5520 can protect DDos attack and sync flood ?I have problem on this, so how can i protect on this, some time i saw on my log like this"sync flood " or "ddos to xxx.xxx.xxx.xxx" the ip address random .
We have an ASA 5505 and we keep getting short bursts of ICMP packets (5000 in one second) They will do this and it just simply overloads the ASA and it crashes.Is this since it is 1000 past the 4000 connections per second capacity of the ASA 5505 or do we have a setting wrong some place that could prevent this type of overload from happening? We are looking to prevent DoS and other attacks that prevent even a short loss of connection since the servers are getting attacked daily and we have voice streaming on through the ASA. [code]
Whenever I start a Cisco VPN from any machine on the network, DNS requests to the DIR-655 stop working. If I reboot the router, DNS starts working again (the VPN was left on). Why starting the Cisco VPN would freak out the router?
I was just checking my router's firewall log and I noticed a couple of entries which appear somewhat suspicious, amongst all the 'normal' background radiation of (mainly) Russian and Chinese IPs: [code] The source IP for these 'attacks' is/was unused on my internal network.
My router is a Billion BiPAC 7800N running 1.06e firmware. There are a number of devices permanently connected to the internal network and a number which are connected at other times (e.g. desktops, laptops, mobile/cell phones, games consoles). Some are wired, some are wireless. Some have static IPs (none of which are listed in the above 'attacks'), some have dynamic IPs (assigned by DHCP by the router in a range not listed above). The WiFi is secured with a strong key on WPA/WPA2-PSK, AES (no WPS). Web Access Control for the router is disabled. Block WAN PING (and Block WAN (IPv6) PING) are both enabled.
I have the DIR-655 Hardware version B1, Firmware version 2.00NA and everything has been working fine for about 3 months. Lately the internet connection to all the computers would just stop. All the computers are connected to the router and the router is connected to the cable modem and their is no indication of a problem. The lights are all on and the router status shows the cable status as connected and the network status as established. I can't open any webpages, or all the ping would time out. It happens on all device, Windows Vista/7 PC, Mac computer, Linux laptop, and iPhone/ iPad. The problem gets fixed when I reset the router or just wait about 5-10 minutes and the problem goes away. That normally isn't a problem, but it's starting to happen twice a day now and it is really really annoying when I'm playing games. I tried the FAQ and searching the forums, but in vain.
We have a router (7206) which connected to client device in /30 IP segment, but this device is a switch which connected to many more devices. Doing packet capture on our router interface unravel many ARP requests which comes from the client switch.Is there any feature or command which we can stop this?
We are finding the price for ASA 5505 to high and our clients are having problem securing budgets for these devices. We don't want to move to different vendors and we have a team of people we already know Cisco well.I have seen Cisco router 877 which have the ipadvance ios, is this the same as the ASA5505.We would like to offer our clients an alternative to ASA5505, but something which can do the same as a edge device but also protect the client from malicious attacks and has CLI.
I live in a Townhome complex so inSSIDer displays a lot of wireless activity. I have noticed that many of the routers channels are listed as 6 + 2, 4 + 1, etc., while show only a single channel. I have been able to "temporarily" replicate this by setting the Channel Width on my DIR-655, by setting channel width to auto, and when I am successful it displays a speed of 300, both in my task bar and in inSSIDer. However, that is usually short lived and the channel for my router reverts back to a single channel and the displayed speed drops to 130 or 144. My neighbor's Netgear is rock solid at displaying dual channels. Well, that and besting my signal strength. :-)
I have the router manually to channel 8 because none of the routers, judged by their displayed strength, use it.So, I guess my question is; how do I stop my DIR-655 from dropping back to using a single channel, which I interpret 20MHz, even though it is set on auto?
I recently purchased a dir 655 router and it works fine but in after a while of using it, the wifi signal will stop broadcasting my other computers still work with the internet that are hard wired but the ones im using through the wifi signal will loose connection. So my fix has been unplugging the router and plugging it back in then it will broadcast my wifi again. I tryed leaving it plugged in and refreshing and rebooting my computers but that wont fix it until i disconnect the router and plug it back.
Region : Others Model : TL-WR741ND Hardware Version : Not Clear Firmware Version : ISP :
after year and a half of using TL-WR741 ND router, it suddenly stop working during the night. I have no problems with router before this happened (I think only one or two reset in 1 year and 6 months). System led light does not flash (some sytem error) and I can't access to 192.168.1.1 router setup site. I tried almost everything, unplug power, reset etc. for almost 100 times, reconnect the router with modem and PC in all posible ways, but still can't establish connection or even access to router's setup. Obviusly internet works fine?
I have 3 cameras. all had the problem that after a while motion detection would be triggered continuously for no reason at all. With 2 of them I managed to fix it with a firware update, but no luck with the 3rd one. I even tried several different firmware versions.) it starts to record continuously after abt 24-48 hrs & i have to reboot to get it to stop.
My younger brother uses IDM to download files and it slows my Internet down to a crawl. I've tried reasoning with him but its not getting through to him. Is there any way I can use my router (bcz only I have access to it) to limit IDM?
I recently switched from a DSL ISP (Earthlink, Zyxel modem configured as a bridge, pppoE connect) to a cable ISP (Comcast, Arris cable modem, dhcp connect). Basically PC --> DIR615-->Cable modem-->Internets. With the old DSL the Internet activity LED (green, looks triangular) on the DIR615 blinked only when internet activity occurred. With the new Comcast connection it blinks non-stop about 5 times a second! Even if the PC is turned off it blinks. It stops blinking if I disconnect the ethernet cable between router and modem. The connection itself is fine, but if the DIR615 is doing something it should not be doing it might slow the connection down a bit, (or burn something out prematurely?)FYI, the Arris cable modem does not seem to be a router. It takes a cable connection from outside and provides a single ethernet cable and 2 (voice) telephone cables to the house.
I am using a USB Wireless Lan card to connect to the WiFi for over a year now. Never had any problems. Today suddenly i am unable to locate my WiFi router. This said I am able to see my neighbors router and am also able to connect to it. My router is working on other computers connected through WiFi. Now I have connected to the router through Ethernet and it is working. I would like to connect through WiFi only
Region : India Model : TL-MR3220 Hardware Version : V1 Firmware Version : 3.14.2 Build 120817 Rel.55520n ISP : Tata Photon Whiz
I just bought the TP Link MR 3020 and tried connecting my Tata Photon Whiz USB (Huawei EC121) modem with it. The TP Link cannot identify the modem. It goes forever into identifying mode. I next tried a Huawei E173 with Reliance 3g sim in it but again no results. The TP Link goes into identifying mode forever. I have installed the latest firmware for the device but am not able to set it up.
I am about to buy a Netbook from HP with windows 7 Starter.But a few days back when I tried to connect my friend's laptop to my network using WiFi ,it accessed the Internet but did not detect any other XP computers on the Network neither could I ping them nor could I access their shared folders.
2)And What is N Draft?? and how is it different from WiFi-N?
3)And can I set up Guest Network so that I can give the connected computers Internet access but no Shared Folder access..
Region : Egypt Model : TL-MR3420 Hardware Version : V1 Firmware Version : TL-MR3420_V1_120523 ISP : Etisalat Egypt
TL-MR3420 failed to detect " ZTE MF190S " Egypt Etisalat USB Dongle, and the file for the attached model can't be found on the 3G Modem Bin File Center.
Region : Malaysia Model : TL-MR3220 Hardware Version : Not Clear Firmware Version : 3.13.12 Build 120703 Rel.58323n ISP :
I'm using the TL-MR3220 hardware version 2.0. Firmware version 3.13.12 Build 120703 Rel.58323n. I'm using D-Link DWM-156 3.75G HSUPA USB Adapter.The problem I'm encountering is the router does not auto detect the 3G USB adapter when I power up the router. The router will detect the 3G adapter only when I plug out and plug in the 3G USB adapter. I used to have the same router but version 1.2. Version 1.2 does not have this problem.
Region : India Model : TL-MR3220 Hardware Version : V1 Firmware Version : TL-MR3220_V1_121123 ISP : Reliance Netconnect +
I have reliance ZTE AC2726 modem and i am trying to connect it with using the latest firmware version 121123. Router is able to detect the modem but when it tries to dial the connection is not established and reset the router after retrying 2-3 times. It was working perfectly fine earlier when i was on 120309 firmware version. So i tried downgrading my firmware version to 120309 and again it started working. I am not sure why the latest firmware version is not working with this device. Ideally the new firmware versions for a router should fix the existing issues and all the modems which were working earlier should work.
Region : Australia Model : TD-W8950ND Hardware Version : V1 Firmware Version : 1.2.9 build 110212 Rel.22296n
I made some changes on my wireless modem router to stop dhcp and dns provided by my device. A server is now doing it, but at the same time I appear to have connection issues where I didn't before. In an attempt to resolve the issues I looked at the System Log and a number of things were coming up that concerned me. These are as follows:
-user: tr69c: Unable to retrieve attributes in scratch PAD
-user: Stored Parameter Attribute data is corrupt or missing
Additionally I'm getting a lot of kernel: Intrusion alerts which I can't determine how serious they are. Where to start tracking down these issues (if they even warrant investigation).
I having issues with DView 3.11 on a WinXP Professional with SP3.There are 4 DCS 5300G cameras wired to the router.I can see the cameras using IE, but when I try to configure the DView in the camera section with the autodetect button it will show an error that the camera cannot be identified.I had checked the IP address, port, user & pass everything is ok. I even hard reseted one of the cameras and it won't work.
I found intermittent link down(20~40 seconds average) occurred about 1~10 times every month. SAP reported a lot of active connections are disconnected and I used a batch to ping and found "requested time out" about 30 seconds.And Windows, SQL server, Nexus 5010 do not show any errors. We run cluster and cluster does not fail over.And I don't know which cables or nics cause this issue. When it happened, almost all servers are unreachable. For example, SQL server 1 -> SQL server 2, IBM HS22-1 -> SQL server 1. However, some connections are not dropped sometimes. It varies each time.PS: I run this topology last year without any problems but it started intermittent link down from 2011/1/7. Because there is no errors in Nexus 5010, it is difficult to troubleshoot. Cisco TAC recommended us to implement virtual port channel yesterday. Could I use "errdisable detect cause" to detect what caused the intermittent link down? Is there any error logs or switch parameters/status can use to troubleshoot?
If your wireless indicator is flashing red when you discover the smurf, it can mean that someone has tried to logon with an incorrect password. this is not necessarily an attack, it could be someone you have allowed access too, who has forgotten the password? In this case entering the correct password will solve the problem.However putting your own MAC address into the filter will simply block your own machine.