Syn flood
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Help with my Plusnet services
- :
- Full Fibre
- :
- Re: Syn flood
Syn flood
19-11-2025 3:06 PM - edited 19-11-2025 3:11 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I recently noticed that I see a lots of syn packages coming to my router from multiple IP addresses located in Brazil.
Based on my knowledge it's looks like syn flood attack.
I have a few firewall rules added (rate limiting and geo ip blocking) which are helping me to mitigate this kind of network activity so I should be fine, but what I'm curious is this is only me experiencing this kind of traffic or this is some more global campaign across Plusnet network ?
Currently, traffic comes from subnet 45.225.192.0/22 (via AS266948) unless these IPs are spoofed.
Re: Syn flood
19-11-2025 3:10 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
You get this kind of thing from time to time . The Hub should take care of it.
Re: Syn flood
19-11-2025 3:14 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I use my own router with OpenWrt system so I have no issue with handling this kind of traffic. I'm only curious if this is only my currently getting this traffic or more people experiencing this.
Re: Syn flood
19-11-2025 4:57 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Fair enough. I get spells of it, and I'm not with PN, but I see it on a regular basis on most log files I look at.
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page