<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [SYN] Flood? in Tech Help - Software/Hardware etc</title>
    <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/SYN-Flood/m-p/1998727#M97407</link>
    <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/110903"&gt;@mhepplewhite&lt;/a&gt;&amp;nbsp;Personally , wouldn’t worry, apart from filling up your log, this just proves the router is doing it’s job&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Feb 2025 14:21:09 GMT</pubDate>
    <dc:creator>jab1</dc:creator>
    <dc:date>2025-02-12T14:21:09Z</dc:date>
    <item>
      <title>[SYN] Flood?</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/SYN-Flood/m-p/1998685#M97403</link>
      <description>&lt;P&gt;I am on a home broadband package with a small Pi home server. Port forwarding 443 to said server. Sometime in the recent past the router technical log shows incoming port forwards from remote IPs (seem to be mainly Brazil according to iplocation) at about 1 per second. IP is like A.B.C.D where A.B stays the same &lt;SPAN&gt;for a day or two&amp;nbsp;&lt;/SPAN&gt;but C.D changes. Wireshark capture shows server responds with [SYN, ACK] but there is no response from remote IP. Server resends a few times then a [RST] is received. Source location has also been identified as e.g. Korea.&lt;/P&gt;
&lt;P&gt;No web pages are requested.&lt;/P&gt;
&lt;P&gt;I am struggling to figure out what is going on or whether any defensive action is needed. Server loading seems to be minimal. Main impact seems to be that the PlusNet 2 router FW Log fills up in a short period.&lt;/P&gt;
&lt;P&gt;Advice and insights gratefully received.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 11:29:42 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/SYN-Flood/m-p/1998685#M97403</guid>
      <dc:creator>mhepplewhite</dc:creator>
      <dc:date>2025-02-12T11:29:42Z</dc:date>
    </item>
    <item>
      <title>Re: [SYN] Flood?</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/SYN-Flood/m-p/1998711#M97404</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/110903"&gt;@mhepplewhite&lt;/a&gt;&amp;nbsp; Any open port is going to attract unwanted attention. Syn Floods are just attempts to disrupt your system.&amp;nbsp;&lt;BR /&gt;Nothing to worry about, I just ignore them unless further problems develop….&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 13:04:12 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/SYN-Flood/m-p/1998711#M97404</guid>
      <dc:creator>Champnet</dc:creator>
      <dc:date>2025-02-12T13:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: [SYN] Flood?</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/SYN-Flood/m-p/1998712#M97405</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/893"&gt;@Champnet&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;... just ignore them unless further problems develop….&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and if they DO become a problem, then Dave can take a look to see what can be done (see &lt;A href="https://community.plus.net/t5/Full-Fibre/TCP-SYN-Attack-Changing-IP/m-p/1995766#M26261" target="_self"&gt;TCP SYN Attack / Changing IP&lt;/A&gt; )&lt;/P&gt;
&lt;P&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 13:09:17 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/SYN-Flood/m-p/1998712#M97405</guid>
      <dc:creator>outcast</dc:creator>
      <dc:date>2025-02-12T13:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: [SYN] Flood?</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/SYN-Flood/m-p/1998721#M97406</link>
      <description>Thank you very much, reassuring. It's just that that port has been open for ages, and, as you say, various random IPs try out some standard things, but the repeated [SYN] thing is more recent. &lt;BR /&gt;Changing IP is a bit of a mixed blessing as various settings need to be updated.</description>
      <pubDate>Wed, 12 Feb 2025 13:57:59 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/SYN-Flood/m-p/1998721#M97406</guid>
      <dc:creator>mhepplewhite</dc:creator>
      <dc:date>2025-02-12T13:57:59Z</dc:date>
    </item>
    <item>
      <title>Re: [SYN] Flood?</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/SYN-Flood/m-p/1998727#M97407</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/110903"&gt;@mhepplewhite&lt;/a&gt;&amp;nbsp;Personally , wouldn’t worry, apart from filling up your log, this just proves the router is doing it’s job&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 14:21:09 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/SYN-Flood/m-p/1998727#M97407</guid>
      <dc:creator>jab1</dc:creator>
      <dc:date>2025-02-12T14:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: [SYN] Flood?</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/SYN-Flood/m-p/1998733#M97408</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/110903"&gt;@mhepplewhite&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am on a home broadband package with a small&lt;STRONG&gt; Pi home server&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="1739369651174"&gt;... ...&lt;/P&gt;
&lt;P&gt;Main impact seems to be that the PlusNet 2 router FW Log fills up in a short period.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/110903"&gt;@mhepplewhite&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you are already tech savvy enough to build a Pi server,&amp;nbsp; have you considered building a pfSense router ?&lt;/P&gt;
&lt;P&gt;I use pfSense for many things, but related to your question, when I add a port forward, rather than having that port open to the world (as happens with the Plusnet Hub-2), I block ALL external access then add a firewall whitelist of allowed/known external IP addresses that can access that port - so as not to attract the attention of port scanners from anywhere in the world.&lt;/P&gt;
&lt;P&gt;For example, I've configured my router's WAN port to reply to PING requests, but only specific test sites that I use (such as the ThinkBroadband &lt;A href="https://www.thinkbroadband.com/faq/broadband-quality-monitor" target="_self"&gt;BQM server&lt;/A&gt;) can see the open port.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TBB BQM server address.png" style="width: 685px;"&gt;&lt;img src="https://community.plus.net/t5/image/serverpage/image-id/59683iFEA1C36D641C7EA8/image-size/large?v=v2&amp;amp;px=999" role="button" title="TBB BQM server address.png" alt="TBB BQM server address.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 14:33:03 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/SYN-Flood/m-p/1998733#M97408</guid>
      <dc:creator>outcast</dc:creator>
      <dc:date>2025-02-12T14:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: [SYN] Flood?</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/SYN-Flood/m-p/1998759#M97409</link>
      <description>&lt;P&gt;Thank you - I will consider such an option, thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 17:07:10 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/SYN-Flood/m-p/1998759#M97409</guid>
      <dc:creator>mhepplewhite</dc:creator>
      <dc:date>2025-02-12T17:07:10Z</dc:date>
    </item>
    <item>
      <title>Re: [SYN] Flood?</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/SYN-Flood/m-p/1998760#M97410</link>
      <description>&lt;P&gt;&lt;A href="https://community.plus.net/t5/My-Router/Blocking-ip-addresses-for-incoming-traffic-with-Hub-Two/m-p/1998463#M40939" target="_self"&gt;Here are a few YouTube videos&lt;/A&gt; to give you an idea of what might be involved with building your own router.&lt;/P&gt;
&lt;P&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 17:12:42 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/SYN-Flood/m-p/1998760#M97410</guid>
      <dc:creator>outcast</dc:creator>
      <dc:date>2025-02-12T17:12:42Z</dc:date>
    </item>
  </channel>
</rss>

