cancel
Showing results for 
Search instead for 
Did you mean: 

DNS issues and IDS

AtariMark
Newbie
Posts: 4
Registered: ‎01-03-2014

DNS issues and IDS

I noticed there are a lot of posts about DNS issues. My issue is similar but not the same. About 2 weeks ago I kept having problems getting to some sites, a router reboot fixed this but it got steadily worse and now it is extremely frustrating as a lot of site fail.
Yesterday I did a reset on the gui so it was back to default settings but still I have the problem. I changed the DNS on my PC to use googles public address (8.8.8.8) but that fails as well. I changed the DNS on the router to 8.8.8.8 and that didn't work.
I looked in the logs on the router and when it fails I can see the IDS blocking connections
Mar 15 15:52:04 IDS dos parser : udp flood (1 of 2) : 217.23.186.193 46.208.220.4 0143 UDP 19556->63132
Error Mar 15 15:51:44 FIREWALL replay check (1 of 3): Protocol: ICMP Src ip: 195.88.43.22 Dst ip: 46.208.220.4 Type: Destination Unreachable Code: Port Unreacheable
Warning Mar 15 15:51:44 IDS scan parser : udp port scan: 95.188.132.128 scanned at least 20 ports at 46.208.220.4. (1 of 1) : 95.188.132.128 46.208.220.4 0132 UDP 4630->62983
Error Mar 15 15:50:56 IDS dos parser : udp flood (1 of 2) : 37.204.51.163 46.208.220.4 0132 UDP 1537->62981
Error Mar 15 15:50:35 FIREWALL replay check (1 of 2): Protocol: ICMP Src ip: 111.172.91.206 Dst ip: 46.208.220.4 Type: Destination Unreachable Code: Port Unreacheable
Error Mar 15 15:49:19 IDS dos parser : udp flood (1 of 3) : 188.230.113.246 46.208.220.4 0143 UDP 6881->62983
Error Mar 15 15:46:47 IDS dos parser : udp flood (1 of 1) : 178.91.7.222 46.208.220.4 0143 UDP 6881->62695
Error Mar 15 15:42:59 IDS dos parser : udp flood (1 of 1) : 93.123.181.65 46.208.220.4 0143 UDP 1024->62109
Error Mar 15 15:42:14 FIREWALL icmp check (1 of 1): Protocol: ICMP Src ip: 87.110.120.80 Dst ip: 46.208.220.4 Type: Destination Unreachable Code: Host Unreacheable
Error Mar 15 15:40:49 IDS dos parser : udp flood (1 of 1) : 31.181.108.243 46.208.220.4 0143 UDP 6881->61561
I just did an nslookup on www.bbc.co.uk and it failed for both the default DNS server at plusnet and googles (8.8.8.8)
Server:  UnKnown
Address:  192.168.1.254
DNS request timed out.
    timeout was 2 seconds.
DNS request timed out.
    timeout was 2 seconds.
DNS request timed out.
    timeout was 2 seconds.
DNS request timed out.
    timeout was 2 seconds.
*** Request to UnKnown timed-out
> server 8.8.8.8
DNS request timed out.
    timeout was 2 seconds.
Default Server:  [8.8.8.8]
Address:  8.8.8.8
> www.bbc.co.uk
Server:  [8.8.8.8]
Address:  8.8.8.8
DNS request timed out.
    timeout was 2 seconds.
DNS request timed out.
    timeout was 2 seconds.
DNS request timed out.
    timeout was 2 seconds.
DNS request timed out.
    timeout was 2 seconds.
*** Request to [8.8.8.8] timed-out
>
I just googled  "plusnet IDS" and there was an ad for www.plus.net so I clicked it and .... yes failed to connect. The actual error in chrome is failed to load www.googleadservices.com
I looked in the router logs and got this
Error Mar 15 16:06:08 FIREWALL replay check (1 of 1): Protocol: ICMP Src ip: 111.172.91.206 Dst ip: 46.208.220.4 Type: Destination Unreachable Code: Port Unreacheable
Error Mar 15 16:05:30 IDS dos parser : udp flood (1 of 1) : 95.59.14.34 46.208.220.4 0143 UDP 10230->63632
All my PCs are affected so I don't believe it is a virus. I am using Windows XP, Win7, Win8.1 and Android and all are affected.
Any ideas? Has anyone else got this? It making my internet unusable.
4 REPLIES 4
AtariMark
Newbie
Posts: 4
Registered: ‎01-03-2014

Re: DNS issues and IDS

Had another look at the IDS on my router and it looks like there has been a lot of blocking
udp_rate_limiting 1153898
ejs
Aspiring Hero
Posts: 5,442
Thanks: 631
Fixes: 25
Registered: ‎10-06-2010

Re: DNS issues and IDS

Port 6881 is a default port number used by bittorrent, so the IDS log messages could be due to large amounts of bittorrent traffic.
cjcshadowsan
Grafter
Posts: 42
Registered: ‎10-11-2011

Re: DNS issues and IDS

AtariMark - can you get in touch please over pm?
Regards,
Chris
AtariMark
Newbie
Posts: 4
Registered: ‎01-03-2014

Re: DNS issues and IDS

Quote from: ejs
Port 6881 is a default port number used by bittorrent, so the IDS log messages could be due to large amounts of bittorrent traffic.

I rarely use bittorrent so no idea why I am getting them.