Page 1 of 1

Thousands of Connections established with mikrotik

Posted: Thu Aug 05, 2010 6:12 pm
by inertia
I am using an RB1000 for my network. I have got only about 200 customers but in the IP firewall connections i could see thousands of connections being established which does not seem right. It looks to me like there is an script running on someone's pc which is establishing all the fake connections. Any advise?

Re: Thousands of Connections established with mikrotik

Posted: Fri Aug 06, 2010 9:48 pm
by fewi
When 200 users each have 5 connections (like loading one web page with 4 pictures embedded) that'll be 1,000 connections showing.
You can try lowering the time outs in "/ip firewall connection tracking" but it's still perfectly normal to show more connections that you have user, because each user can have dozens of connections quite legitimately.

Re: Thousands of Connections established with mikrotik

Posted: Fri Aug 06, 2010 10:56 pm
by inertia
yeah you are right, but i think i cannot explain my problem properly. I think my system is under DoS attack. I could see burst of data coming in from the ethernet port of rb1000 which is connected to my backhaul. After around every 30 seconds or so i got a burst of data of around 60-70 Mb coming into rb1000. My system usage also shoots up to 100 %. I have tried adding few firewall rules which has supressed the problem but still i could not find a perfect solution for it.

Re: Thousands of Connections established with mikrotik

Posted: Fri Aug 06, 2010 11:09 pm
by fewi

Re: Thousands of Connections established with mikrotik

Posted: Mon Aug 09, 2010 3:18 am
by MCT
That's odd, 60-70mbps shouldn't even phase the RB1000. Do you have any captures of that traffic? The only way to really see what is happening is to get a good look at that traffic burst and work out why it's maxing the CPU on the routerboard.

Re: Thousands of Connections established with mikrotik

Posted: Mon Aug 09, 2010 3:34 pm
by leonset
What really stresses a router like RB1000 are packets per second and not bandwidth, because every packet has to be analized and checked against firewall, mangle, routing, etc, etc. Having the right order in your firewall rules does help to withstand Dos Attacks/Traffic Peaks.