Hello guys,[:)]
i have the following problem on our asg:
I am constantly checking the packet filter violation reports and they are on average at 300 - 2000 short peak. But today i saw a new record peak at 7000 for a not that short period of time. So i checked the Packet filter violation logs files and found out that we are constantly receiving packets from various ips with 2 common destination ports 1st 12330 and 2dn 62505 - tcp and udp. Ip destination is our asg.
To me this looks like a bot net attack.
I couldnt find out anything useful about the dest ports nor doest it seem to be a real issue at the moment.
But i do not intend to let it get one either.
Do u have any suggestions how to handle this matter, avoid denial of service or worse?
For your conveniance i will post an extract of the concerning log file in the attachments.
As i said the source ips are variing.
Thanks in advance for hopefully quick replies.
This thread was automatically locked due to age.