Page 1 of 1
IP 31.6.71.253 & 31.6.71.254
Posted: Wed May 20, 2015 8:50 pm
by jfvelamoscoso
I am getting on torch a lot of traffic upload to this ip:
31.6.71.253
31.6.71.254
But there is no user behind this router, looks like the router is uploading this information.
Does anyone know what service is uploading? or Why is this?
Re: IP 31.6.71.253 & 31.6.71.254
Posted: Wed May 20, 2015 9:05 pm
by pukkita
Do you have assigned ips in that range? to which ports does the traffic go? Its probably either network (port) probing or scanning; maybe your ISP has set routing improperly.
BTW there's a typo in your sig, guess you meant MTCTCE

Re: IP 31.6.71.253 & 31.6.71.254
Posted: Wed May 20, 2015 9:06 pm
by jfvelamoscoso
I found also this IP
103.243.20.43
94.190.193.121
201.34.145.201
209.216.126.207
189.79.40.16
192.185.26.193
194.6.233.17
Re: IP 31.6.71.253 & 31.6.71.254
Posted: Wed May 20, 2015 9:08 pm
by jfvelamoscoso
This IP are found on Source address, and the destination is the router.
On ip firewall connections.
I can find different source porte but the destination port is always the same 53. This traffic is unexpected because as i said there is no host behind the router. Looks like the router is uploading all of this traffic
Re: IP 31.6.71.253 & 31.6.71.254
Posted: Wed May 20, 2015 9:10 pm
by pukkita
could you post a screenshot from ip > firewall > connections??
Re: IP 31.6.71.253 & 31.6.71.254
Posted: Wed May 20, 2015 9:11 pm
by jfvelamoscoso
I forgot to tell the traffic is more than 3 Mbps which is too much for dns
Re: IP 31.6.71.253 & 31.6.71.254
Posted: Wed May 20, 2015 9:15 pm
by chechito
Re: IP 31.6.71.253 & 31.6.71.254
Posted: Wed May 20, 2015 9:25 pm
by pukkita
chechito: it varies from day day... this morning were russian ips, right now are turkish, later may be chinese ips...
If your router is really exposed to the Internet (i.e. not an ADSL o FTTH line) a good firewall, that adds "probing" or port scanning source IPs to dynamic address lists for further firewall drop is mandatory.
Re: IP 31.6.71.253 & 31.6.71.254
Posted: Wed May 20, 2015 9:35 pm
by jfvelamoscoso
I found the problem. My router was been used as a DNS Server and it has allowed request activate.
Re: IP 31.6.71.253 & 31.6.71.254
Posted: Wed May 20, 2015 9:52 pm
by chechito