TCP SYN Packet Attack After the Firmware Upgrade

TCP SYN Packet Attack After the Firmware Upgrade

TCP SYN Packet Attack After the Firmware Upgrade
TCP SYN Packet Attack After the Firmware Upgrade
2024-01-05 01:25:12 - last edited 2024-02-06 02:40:40

This Article Applies to:

 

All Omada routers.

 

Issue Description/Phenomenon:

 

We received feedback after the upgrade of the Omada routers in a recent firmware release(by the time of this thread), your controller will show the log of XYZ Detected TCP SYN packet attack and dropped 123 packets.

 

Available Workarounds/Solutions:

 

First, it is an expected symptom if you have enabled/tweaked the firewall parameters - Block TCP scan with RST. By default, this is disabled.

If a connection sends a TCP SYN to the router, the router will respond with an RST.  It will be recorded and the controller will report it every 10 minutes to you in the log.

 

Note that the log is supposed to record what should be there or what is happening which is what the log does. And we are enriching the log system to be more specific and detailed. To some users, this might be confusing or bothering. Please use the User Guide and Google wisely. If you don't prefer the log repeatedly showing up in your controller, you may disable it.

 

Available Solution:

 

Disable the Block TCP scan with RST.

This will not respond with an RST instead it will instantly drop the connection without replying anything.

 

Related Reading: Omada Gateway Cannot Get Full Stealth On The GRC ShieldsUp Test. [Case Closed]

Q&A 3 in Understanding TCP/UDP and How Omada Firewall Protects Your Network from Attacks

 

Thank you for your attention!

 

Update Log:

 

Jan 5th, 2024:

Release of this article.

 

Feedback:

 

If this was helpful, welcome to give us Kudos by clicking the thumbs-up button below.

 

If the solution doesn't work for you, your case is probably different from what is described here.

In that case, please feel free to click Start a New Thread and elaborate on the problem so that we can try to help you further.

 

Thank you for your great cooperation and patience!

TP-Link Support Team

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Beta firmware got some NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting Manual ★ ☚ (Disclaimer: Short links are used above solely for guidance to TP-Link subdomains and are safe and tracker-free. Exercise caution with short links from non-official members on forums. We are not liable for external content or damage from non-official members' link use.)
  3      
  3      
#1
Options
2 Reply
Re:TCP SYN Packet Attack After the Firmware Upgrade
2024-01-05 02:18:15

Hi  @Clive_A ,

 

I believe a 60-minute interval would be more suitable, as having a log entry every 10 minutes results in 144 entries per day. With a 60-minute frequency, you'd only receive 24 logs daily, preventing clutter.

  0  
  0  
#2
Options
Re:TCP SYN Packet Attack After the Firmware Upgrade
2024-01-05 13:37:38

  @di-vin 

 

makes it very hard to debug at 60mins if it's an internal device attcking the router.

  0  
  0  
#3
Options