cancel
Showing results for 
Search instead for 
Did you mean: 

Should I be worried

kreynolds
Grafter
Posts: 433
Registered: 05-04-2007

Should I be worried

My Netgear DG834 Log is showing the following

UDP Packet - Source:212.159.13.50,53 Destination:80.229.140.69,1404 - [DOS]
UDP Packet - Source:212.159.13.50,53 Destination:80.229.140.69,1411 - [DOS]
UDP Packet - Source:212.159.13.49,53 Destination:80.229.140.69,1406 - [DOS]
UDP Packet - Source:212.159.13.49,53 Destination:80.229.140.69,1411 - [DOS]
UDP Packet - Source:84.92.5.187,51692 Destination:80.229.140.69,8000 - [DOS]

timed @ 17:31

and

UDP Packet - Source:212.159.13.50,53 Destination:80.229.140.69,1406 - [DOS]
timed @ 14:58

IP 84.92.5.187 is showing as originating from PlusNet Network Infrastructure,and the others are the DNS Servers. All are showing as Denial Of Service.

Any thoughts?
3 REPLIES
Highlighted
kreynolds
Grafter
Posts: 433
Registered: 05-04-2007

Should I be worried

Anyone :?: :?:
Community Veteran
Posts: 14,469
Registered: 30-07-2007

Should I be worried

The first 4 are delayed DNS lookup return packets from PNs DNS servers (212.159.6.9 & .10, 212.159.13.49 & .50) and can be ignored.

The fifth one is just normal internet 'noise' which everyone gets and can also be ignored.

None of the packets are DOS, your router, like many others, is incorrectly reporting it as such and thus making your think there is something bad happening. I normally disable logging of DOS as it is just a waste of time.

DOS (deniel of service) is where you get many hundreds/thousands of packets being sent to you to in a very short period of time (measured in seconds) to disrupt your connection. Having just a few is perfectly normal on the internet today and is what your firewall is there for.
kreynolds
Grafter
Posts: 433
Registered: 05-04-2007

Should I be worried

Phew Smiley

Thanks for that