Ping attacks and TCP-no flag attacks
Ping attacks and TCP-no flag attacks
Is there anything in the router config that can help prevent ping attacks and TCP no-flag attacks?
This is a new install. I've been seeing a few of these a day.
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
@Ajcke The controller has a security section that allows you to block this kind of stuff. now there is no reason to do so, unless there is an active incident running. Most operating systems from this century have long included countermeasures against this.
- Copy Link
- Report Inappropriate Content
preventing that from changing your ip address. so the guy will stop attacking you.
but anyway, if you surf on the internet, you can be found by the ip address. use customized DNS to mask your ddns and ip
- Copy Link
- Report Inappropriate Content
The Omada controller was offline for a few hours again today, but I'm not seeing in the controller why. Maybe the Ping attacks and TCP-no flag attacks had nothing to do with the last event. Screenshots of what's in the network security section are listed below. Should I be looking in the controller or router GUI to why the Ping attacks and TCP-no flag attacks are occurring? Anything you recommend to modify?
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
@Ajcke I recommend you to disable all those "packet anomaly" options, and only keep "Block TCP Packets with SYN and FIN Bits Set" and "Block TCP Packets with FIN Bit but No ACK Bit Set" ticked.
All the other "protections" are for bugs in ancient, unsupported operating systems. one that suggest you to block fragmented traffic is particulary evil since having fragmented traffic on the internet is sub-optimal/annoying but otherwise ok.
in the Firewall Options section leave ON only "syn cookies" options since you can live fine without (send/recieve) icmp redirects and broadcasts pings.
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
Information
Helpful: 0
Views: 2199
Replies: 18
Voters 0
No one has voted for it yet.