ER8411

I am receiving a lot of TCP SYC Attacks. Is there any way in the web interface or console to see the source IP address where these are coming from?
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content

Hi @Buffalo-Run
Thanks for posting in our business forum.
No.
Understanding TCP/UDP and How Omada Firewall Protects Your Network from Attacks
- Copy Link
- Report Inappropriate Content
@Buffalo-Run Was browsing through the forums and came across this post. I have my ER8411 system log logging to my server with KIWI SYSLOG SERVICE MANAGER which is a free program.
I was checking my logs and came across the same TCP SYN attacks and found this in the logs:
03-26-2025 08:08:23 User.Warning 10.1.1.1 Mar 26 08:08:24 ER8411: 2025-03-26 08:08:24 firewall<4>: [OMADA]117.245.47.19855 Detected TCP SYN packets attack and dropped 154 packets.
03-26-2025 08:18:30 User.Warning 10.1.1.1 Mar 26 08:18:30 ER8411: 2025-03-26 08:18:30 firewall<4>: [OMADA]185.242.226.2655 Detected TCP SYN packets attack and dropped 160 packets.
Despite the extra 5 being tacked onto the end of the last octet, I believe those are the IP's sending the TCP SYN packet attacks. Perhaps this may help you.
- Copy Link
- Report Inappropriate Content

Hi @Buffalo-Run
Thanks for posting in our business forum.
No.
Understanding TCP/UDP and How Omada Firewall Protects Your Network from Attacks
- Copy Link
- Report Inappropriate Content
@Buffalo-Run Was browsing through the forums and came across this post. I have my ER8411 system log logging to my server with KIWI SYSLOG SERVICE MANAGER which is a free program.
I was checking my logs and came across the same TCP SYN attacks and found this in the logs:
03-26-2025 08:08:23 User.Warning 10.1.1.1 Mar 26 08:08:24 ER8411: 2025-03-26 08:08:24 firewall<4>: [OMADA]117.245.47.19855 Detected TCP SYN packets attack and dropped 154 packets.
03-26-2025 08:18:30 User.Warning 10.1.1.1 Mar 26 08:18:30 ER8411: 2025-03-26 08:18:30 firewall<4>: [OMADA]185.242.226.2655 Detected TCP SYN packets attack and dropped 160 packets.
Despite the extra 5 being tacked onto the end of the last octet, I believe those are the IP's sending the TCP SYN packet attacks. Perhaps this may help you.
- Copy Link
- Report Inappropriate Content
Hi @knightmare
Thanks for posting in our business forum.
Good to know that syslog can reveal this information. I don't know it since I don't experience this attack in my environment and I have set up syslog for it.
- Copy Link
- Report Inappropriate Content

Information
Helpful: 0
Views: 231
Replies: 3
Voters 0
No one has voted for it yet.