Page 1 of 1

High upload - security breach?

Posted: Mon Nov 28, 2016 6:54 pm
by spaske84
Hi,

I've noticed that on our network upload on public IP is constantly high and up to the max. Bu using Torch I've noticed that all IPs with high Tx rate originate in China. By checking I don't think that this traffic comes from our LAN network. There are couple of VPN tunnels on the router also. Do you have any idea how to see where does this traffic comes from (and block) or how to even manually block Chinese IPs. Thanks.

Re: High upload - security breach?

Posted: Mon Nov 28, 2016 7:02 pm
by juanvi
disable ip/dns/allow remote requests

Re: High upload - security breach?

Posted: Mon Nov 28, 2016 7:05 pm
by tr00g33k
On which port do they connect if it is UDP 53, be sure to block remote DNS requests

under IP->DNS->Allow remote request untick the box

or with firewall
/ip fire filter chain=input in-interface=WAN protocol=UDP dst-port=53 action=drop
Otherwise make a torch on LAN interface and see the connections

Re: High upload - security breach?

Posted: Tue Nov 29, 2016 10:12 am
by spaske84
Yup, disabling remote DNS requests solved the issue. Thanks a lot guys, you are the best!