Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos UTM Firewall Being Flooded With UDP Packets

Okay I have a Sophos UTM 9 Firewall set up. I have built two BIND DNS servers; one internal for doing recursive queries and one for an external domain with no recursion (so it doesn't act as if it's an open resolver.) 

I've correctly configured DNATs for external as follows:

And the following Firewall Rule:

Everything works fine when turned on, except my Firewall log keeps getting hammered with traffic:

on port 53 from several different random public IPs.

 

I've done some research online, and have read in many cases that this is normal. I have IPS on and configured correctly. UDP flood protection on (in which I've set low to test.) 

I've also configured a group of these public IPs to DROP automatically via Firewall rule. Although the packets are being dropped, I'm still being flooded with UDP:53 attempts, and my firewall log keeps building up in the Gigabytes. However if I turned my NAT rule back on along with Firewall rule, these public IPs are able to get in, with the NAT rule taking precedence over the: 

  rule set.

I have millions of packets being filtered daily, all from random IPs on port 53. My CPU doesn't get pegged out, but everything is slow on the DNS side when these rules are turned back on. Should I be putting the external DNS in a DMZ even though it's recursion is turned off? 

 

Thank you for any ideas!



This thread was automatically locked due to age.
Parents Reply Children
  • I have been using afraid for my ddns service, and that is who I was thinking about with a hosted dns setup as well when I wrote the comment.  Running a public DNS server will get you a fair amount of attention you really won't want if you have other options.  I have my home setup as a subdomain of my primary dns name and have that subdomain cnamed to my ddns entry.  I then send this subdomain back to my internal dns servers on the UTM for internal-only resolution.  It seems to work well for me so far.

  • This was reasonable 20 years ago, but not today.  Darrell's advice is good.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • How about instead of criticizing you give reasonable help and suggestions? Isn't that the whole reason for the community forums?

     

    Thank you. 

  • Thanks Darrell.

    I'm going to try this out! 

  • Also Darrell:

     

    What are your thoughts on adding another NIC for the public DNS, naming it DMZ, subnetting it from Internal, and allowing Internal traffic to DMZ, but no traffic from DMZ to Internal? If that makes sense.

  • From a security standpoint, that makes sense and should protect you from most things on your internal network.  However, watch outbound traffic very closely from your DNS server if you go that route.  Harden it completely (CIS benchmark, plus BIND hardening) and monitor it very closely.  Again, since it is a heavily attacked service, it *could* lead to your IP getting blacklisted.  If your DNS is hosted on a dynamic address, it could also lead to it being blocked from some providers as well.  It really is a mixed bag and like Bob said, it is just not as easy as it was in the past.  It won't hurt at all to try for a bit, but I can tell you from experience, removing your (really, your ISP) ip address from blacklists of any sort is a giant PITA.

  • Justin, I've helped a lot of folks here over the years, but I had nothing to add to Darrell's answer.  I apologize if you felt that was criticism - none such intended!  It seemed like you were new to this and I wanted to underline the importance of taking his advice.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • I'm new here in the forums yes, but IT no. I'm just looking for good advice. I've been working with Sophos UTM as a Sys Tech/ Admin at my company for about a year now, and recently pieced together a machine and put Home Edition on it and have been running it on my home network. I know there are a lot of angles when it comes to DNS. I myself usually like to start the hard way and work my way down to an easy solution, in the process understanding everything a lot better. I'm basically testing things for the most part, and just wondered what a lot of other people out there do in similar situations. I know it's an easy solution to do DDNS, but I wanted to try and host it myself just because I can. Idk, it's an IT thing I guess. 

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?