Omega Owners Forum

Please login or register.

Login with username, password and session length
Advanced search  

News:

Please play nicely.  No one wants to listen/read a keyboard warriors rants....

Pages: 1 [2]  All   Go Down

Author Topic: DoS Attack?  (Read 1945 times)

0 Members and 1 Guest are viewing this topic.

Gaffers

  • Omega Queen
  • *****
  • Offline Offline
  • Gender: Male
  • NE Hampshire/Surrey
  • Posts: 11322
    • Ford Ranger Wildtrak
    • View Profile
Re: DoS Attack?
« Reply #15 on: 24 February 2010, 10:17:28 »

Quote
Incoming ICMP type 3s might indicate that a machine on the network is poking around trying to find open ports perhaps?

Maybe you've got a machine that's infected and generating enough outgoing sessions that the router's NAT table is filling up?

Can you look at the NAT entries on the router?

Failing that, put a machine running wireshark or similar on the same segment as the router and watch what's coming and going?

Kevin

This is where my train of thought lies but being fairly inexperienced in this I am not sure.  I have downloaded and tried wireshark, nice tool!  I shall run it again tonight when the internet is having difficulty.  I have no control over the other computers and I dont have access to them all.

The wierd things is that when there is an outage I still get Skype access (although v poor) and I sometimes get access to OOF yet nothing else...
Logged

Kevin Wood

  • Global Moderator
  • *****
  • Offline Offline
  • Gender: Male
  • Alton, Hampshire
  • Posts: 36418
    • Jaguar XE 25t, Westfield
    • View Profile
Re: DoS Attack?
« Reply #16 on: 24 February 2010, 10:32:40 »

Bear in mind that if the router is also a switch you won't see all the traffic on a single port as the switch will learn what machines are on what segments and route the traffic accordingly. In fact you'll see very little other than broadcast traffic. I find the best thing to do is to get an old hub (not a switch) and place it between the router and the rest of the network, WLAN routers, etc. By connecting a machine to that hub and running wireshark you will see everything that goes out or in.

The fact that some connections work normally does make me wonder if it's a logical problem within the router (i.e. NAT table full, not accepting new connections) rather than the link being maxxed out.

You can also try running wireshark on your local machine and see what the symptoms are when you are getting poor connections. Are you getting "unreachable" responses, are packets getting dropped or is throughput just slow, etc?

I find wireshark is a good educational tool. You can read books about how networks work but there's nothing like seeing it in real time. :y

Kevin
Logged
Tech2 services currently available. See TheBoy's price list: http://theboy.omegaowners.com/

Gaffers

  • Omega Queen
  • *****
  • Offline Offline
  • Gender: Male
  • NE Hampshire/Surrey
  • Posts: 11322
    • Ford Ranger Wildtrak
    • View Profile
Re: DoS Attack?
« Reply #17 on: 24 February 2010, 12:37:42 »

Ok interesting findings.

Just spent 15 mins trying to get online and couldnt, every time I tried to get onto a website it failed even though I was connected.  Looking through the wireshark logs it seems the router is performing a "Source Quench (flow Control)" on the requests from my computer (dont know about the others as I am not seeing all their data.

And then as if by magic the ping gets through and it all starts working.  There is obviously something going on with the router, I think a call to customer services Mumbai is on the cards :y
Logged

Kevin Wood

  • Global Moderator
  • *****
  • Offline Offline
  • Gender: Male
  • Alton, Hampshire
  • Posts: 36418
    • Jaguar XE 25t, Westfield
    • View Profile
Re: DoS Attack?
« Reply #18 on: 24 February 2010, 12:43:04 »

Sounds like a resources issue in the router. Maybe it's out of NAT table entries or a misbehaving host on the network has flooded it with cr@p and filled its' buffers.

Either that or it's leaked all its' memory and needs a reboot. ::)

Kevin
Logged
Tech2 services currently available. See TheBoy's price list: http://theboy.omegaowners.com/

Gaffers

  • Omega Queen
  • *****
  • Offline Offline
  • Gender: Male
  • NE Hampshire/Surrey
  • Posts: 11322
    • Ford Ranger Wildtrak
    • View Profile
Re: DoS Attack?
« Reply #19 on: 24 February 2010, 12:45:27 »

Quote
Sounds like a resources issue in the router. Maybe it's out of NAT table entries or a misbehaving host on the network has flooded it with cr@p and filled its' buffers.

Either that or it's leaked all its' memory and needs a reboot. ::)

Kevin

It reboots regularly, automatically or manually I dont know as I am not guarding over it.  When it does reboot it takes as long as an hour to sort itself out....
Logged

Kevin Wood

  • Global Moderator
  • *****
  • Offline Offline
  • Gender: Male
  • Alton, Hampshire
  • Posts: 36418
    • Jaguar XE 25t, Westfield
    • View Profile
Re: DoS Attack?
« Reply #20 on: 24 February 2010, 12:52:45 »

Quote
It reboots regularly, automatically or manually I dont know as I am not guarding over it.  When it does reboot it takes as long as an hour to sort itself out....

 :o
Logged
Tech2 services currently available. See TheBoy's price list: http://theboy.omegaowners.com/

Mr Skrunts

  • Get A Life!!
  • *****
  • Online Online
  • Gender: Male
  • Skruntie Land.
  • Posts: 25680
  • 3.O Elite Saloon with all the toys,
    • 2003 CD 2.2 Auto
    • View Profile
Re: DoS Attack?
« Reply #21 on: 24 February 2010, 16:24:13 »

Quote
Quote
It reboots regularly, automatically or manually I dont know as I am not guarding over it.  When it does reboot it takes as long as an hour to sort itself out....

 :o


Sounds like there is an internal setup issue or timr for a new modem/router.
Logged
Ask yourself :  " WHY do I believe in what I believe?"

Remember that my opinions expressed here are not representative of the opinions of other members on the OOF Forum.

Gaffers

  • Omega Queen
  • *****
  • Offline Offline
  • Gender: Male
  • NE Hampshire/Surrey
  • Posts: 11322
    • Ford Ranger Wildtrak
    • View Profile
Re: DoS Attack?
« Reply #22 on: 24 February 2010, 18:50:39 »

Right, than ks to KW I think I found the issue or at least a workaround.

Looks like the DHCP or the NAT memory is fubarred like Kevin said.  I manually entered my TCP/IP details and boom!  Everything worked!  To check it wasn't a fluke I went to another computer that wasn;t working and did thesame thing, with positive result!

Cheers to all that contributed :y
Logged

Mr Skrunts

  • Get A Life!!
  • *****
  • Online Online
  • Gender: Male
  • Skruntie Land.
  • Posts: 25680
  • 3.O Elite Saloon with all the toys,
    • 2003 CD 2.2 Auto
    • View Profile
Re: DoS Attack?
« Reply #23 on: 24 February 2010, 18:52:57 »

Good result.   :y
Logged
Ask yourself :  " WHY do I believe in what I believe?"

Remember that my opinions expressed here are not representative of the opinions of other members on the OOF Forum.
Pages: 1 [2]  All   Go Up
 

Page created in 0.013 seconds with 17 queries.