Detected WAN ping attack from {IPAddress} and dropped {count} packets

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Detected WAN ping attack from {IPAddress} and dropped {count} packets

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Detected WAN ping attack from {IPAddress} and dropped {count} packets
Detected WAN ping attack from {IPAddress} and dropped {count} packets
2025-01-24 10:11:20
Tags: #ACL
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.2.6(latest)

Hi,

 

It seems someone / thing is trying to continiously ping my public IP address.

Now i want to block it, found this thread and tried the method as Clive described. "detected WAN Ping attack from xxx.xxx.xxx.xxx" - Business Community 

Point is, i still get the same logs. 

 

ACL configured as Gateway ACL:

Direction > Wan IN

Policy > Deny

Protocols > All

 

Source > An IPgroup with 71.18.0.0 / 16 as subnet AND 117.144.213.0 / 24 as subnet

Destination > IPGroup_Any, An IPgroup which points to the WAN ip/32, and an IPgroup pointing towards the router via local IP. 

 

Anything i possibly have been forget?

 

Thanks in advance!

 

Regards,

 

 

  0      
  0      
#1
Options
4 Reply
Re:Detected WAN ping attack from {IPAddress} and dropped {count} packets
2025-01-26 00:37:44

Hi @Naldjer 

Thanks for posting in our business forum.

I am not sure if I am reading the correct setup.

Do you have a screenshot of how you configured it?

 

If this really bothers you, you can disable this notification in the log settings.

  1  
  1  
#2
Options
Re:Detected WAN ping attack from {IPAddress} and dropped {count} packets
2025-01-26 21:36:04 - last edited 2025-01-26 21:37:27

Hey  @Clive_A 

 

Hereby some screenshots of my setup.


1. ACL

 

2. IP group Block_WanAttacks

 

 

3. WANIP (IPGroup)

 

 

Furthermore its not really the log that bothers me, i just want to have it blocked entirely.

  0  
  0  
#3
Options
Re:Detected WAN ping attack from {IPAddress} and dropped {count} packets
2025-01-27 00:55:14

Hi @Naldjer 

Thanks for posting in our business forum.

Naldjer wrote

Hey  @Clive_A 

 

Hereby some screenshots of my setup.


1. ACL

 

2. IP group Block_WanAttacks

 

 

3. WANIP (IPGroup)

 

 

Furthermore its not really the log that bothers me, i just want to have it blocked entirely.

Log of the IPs.

  0  
  0  
#4
Options
Re:Detected WAN ping attack from {IPAddress} and dropped {count} packets
2025-01-27 07:59:23

Hey  @Clive_A 

 

Thanks again!

 

Hereby the logs.

 

 

Many thanks!

 

Regards,

  0  
  0  
#5
Options