This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

DDoS attack shutting down external interfaces

Hello,

I am having a horrible issue with the Astaro Gateway 7.405 software.

We are experiencing a DDoS attack currerntly and for the last few days.  The attack according to the Astaro is an ICMP flood orginating from a rotating list of about 30 IP addresses.  

The problem is that even though it isn't even really consuming our bandwidth, it is making the External Interfaces on the Astaro no longer route traffic in or out.

All I have to do is go to Network/Interfaces and hit the red right on all external interfaces and then wait a moment and then hit the green light and then all is well for an unknown period of time.  Maybe 10 minutes it will happen again, maybe 4 hours.  Sometimes the interfaces will start working on their own hours later.

This is incredibly frustrating and destroying our faith in the Astaro.  Even a cheap gateway router is handling the attacks far better.

If anyone knows what can be done to correct this, please let me know.  I think it is a serious bug in the Astaro software.  Currently I can't even log into our network remotely because the Astaro's external ports need reset again.


This thread was automatically locked due to age.
Parents
  • In order to protect yourself from IP spoofing you should enable the spoofing filter, go to WebAdmin > Network Security > Packet Filter > Advanced and set the Spoof Protection to Normal or even "strict".

    regards
    Gert
  • If you have support, I suggest that you open a case so they can investigate the issue; my guess is that there is some sort of configuration issue... I've "smashed" some test installs before, and they held up well.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

Reply
  • If you have support, I suggest that you open a case so they can investigate the issue; my guess is that there is some sort of configuration issue... I've "smashed" some test installs before, and they held up well.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

Children
No Data