davidrwhiting - 29/5/07 at 18:16
Hi,
I've just got a buffalo airstation. I love it. Recently, however, I've been
getting log messsages every couple of seconds of this nature:
2007/05/29 18:42:08 FIREWALL TCP connection denied from 82.32.xx.xx:2894
to nn.nn.nn.nn:4662 (vlan1)
[IP addresses changed to protect the innocent]
Each IP appears about 5 times in total, usually not all together. There are
100s of IPs now in my logs. I don't know if this means I've mis-configured
the router or if this is a DOS attack, or just plain normal. Searching for
key phrases has not enlightened me. Anyone got any ideas what is going
on?
Thanks.
David
davidrwhiting - 29/5/07 at 21:27
After a little reading around and checking another log I now think this is
a SYN flood attack. I'm not sure that there is much that I can do about it.
|