I strongly expect that one of my clients was a victim of a DNS Amplification Attack for two days in May 2013.
More on this attack, which made the local news here: http://mybroadband.co.za/news/internet/ ... ttack.html
Symptoms:
* My client reported the internet to be mostly down, with sporadic periods of slow connectivity.
* Pings to the router's WAN IP, resulted on average to about 85% loss.
* I also could not connect to the router remotely or establish a pptp connection.
* The problem went away after the WAN IP was automatically changed by the ISP. (This does not happen often with this ISP, even when rebooting the router)
* When I was able to connect again, I noticed that the PPPoE's traffic for the last 2 days registered 15Gb TX and only about 300Mb RX.
I would like to know:
A. How can I confirm that this attack was the cause of the trouble?
B. How can I prevent this type of attack in the future?
Thank you in advance!
EDIT: The symptoms as described above are once again occurring, as I type this. I can no longer access the router from outside and ping responses report 75%+ loss.