Hi all,
Recently the public DNS we use (8.8.8.
has started showing up in my blocked DDOS address list on the firewall, which has never happened before.
I'm not an expert at all on this stuff... Is something wrong with my DDOS config? Or does this indicate internal clients being part of an attack (perhaps unknowingly?) It's happening based on more than one client, here's what the log entry looks like, obviously 10.0.0.117 is the internal client:
detect-ddos: in:bridge1 out:ether1_Spectrum WAN, src-mac 3c:06:30:15:4a:b0, proto UDP, 10.0.0.117:57852->8.8.8.8:53, len 56
Any insights would be very appreciated,
Dan
Recently the public DNS we use (8.8.8.

I'm not an expert at all on this stuff... Is something wrong with my DDOS config? Or does this indicate internal clients being part of an attack (perhaps unknowingly?) It's happening based on more than one client, here's what the log entry looks like, obviously 10.0.0.117 is the internal client:
detect-ddos: in:bridge1 out:ether1_Spectrum WAN, src-mac 3c:06:30:15:4a:b0, proto UDP, 10.0.0.117:57852->8.8.8.8:53, len 56
Any insights would be very appreciated,
Dan
Statistics: Posted by danriis — Thu Apr 04, 2024 2:18 am