Detected TCP SYN packets attack and dropped - every 10 minutes

Detected TCP SYN packets attack and dropped - every 10 minutes

Detected TCP SYN packets attack and dropped - every 10 minutes
Detected TCP SYN packets attack and dropped - every 10 minutes
2023-11-08 19:48:44 - last edited 2023-11-10 07:09:06
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.2.2
Hello.
I have the latest version of frimware installed, number 2.2.2 Build 20231017 Rel.68869, I have an external IP address and in the logs every 10 minutes there is an entry " [3C-52-A1-F6-27-E8] Detected TCP SYN packets attack and dropped 290 packets "
How to turn it off or block it and how to prevent it from showing up?
I have an ER605v2 router without a controller connected directly to the switch.

 
  0      
  0      
#1
Options
1 Accepted Solution
Re:Detected TCP SYN packets attack and dropped - every 10 minutes-Solution
2023-11-09 02:27:23 - last edited 2023-11-10 07:09:06

Hi @djwujek 

Thanks for posting in our business forum.

Would recommend you take a look at this. Currently, the firmware does not support showing the attack IP. But the ACL can block it by Wiresharking its IP address.

https://community.tp-link.com/en/business/forum/topic/636216

 

Or you can refer to this to turn off the block: Solution Solution to ER605 V1 1.3.0 Firmware Got Many Logs of "TCP no-Flag attack" Issue

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Beta firmware got some NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting Manual ★ ☚ (Disclaimer: Short links are used above solely for guidance to TP-Link subdomains and are safe and tracker-free. Exercise caution with short links from non-official members on forums. We are not liable for external content or damage from non-official members' link use.)
Recommended Solution
  0  
  0  
#2
Options
1 Reply
Re:Detected TCP SYN packets attack and dropped - every 10 minutes-Solution
2023-11-09 02:27:23 - last edited 2023-11-10 07:09:06

Hi @djwujek 

Thanks for posting in our business forum.

Would recommend you take a look at this. Currently, the firmware does not support showing the attack IP. But the ACL can block it by Wiresharking its IP address.

https://community.tp-link.com/en/business/forum/topic/636216

 

Or you can refer to this to turn off the block: Solution Solution to ER605 V1 1.3.0 Firmware Got Many Logs of "TCP no-Flag attack" Issue

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Beta firmware got some NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting Manual ★ ☚ (Disclaimer: Short links are used above solely for guidance to TP-Link subdomains and are safe and tracker-free. Exercise caution with short links from non-official members on forums. We are not liable for external content or damage from non-official members' link use.)
Recommended Solution
  0  
  0  
#2
Options