Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Attack?

Hi, today, in a weekly check on my UTM 9, I noticed that we are receiving thousands of packages from an external ip via port 2074 as an attachment image

The firewall blocks them but it obviously consumes many resources by doing it.


Only yesterday, more than 3 million packages were blocked.


 

In the UTM, is there anything else I can do to improve the UTM's job in blocking this attack?

Tonight I will restart the ISP router but I do not think I can change something.

 

Thanks for any suggestion.

 

 



This thread was automatically locked due to age.
Parents
  • As you do simply drop the package you can't do anything with less impact. Try to find the source of the packages, sometimes the providers do a good job. I had such thing with IPSEC. In the end it was a wrong configured device at the other end. Provider contacted their customer and he corrected this.

    Sometimes attacks are simply wrong configured devices and their traffics hit's somewhere ;-)

     

    Best

    Alex 

Reply
  • As you do simply drop the package you can't do anything with less impact. Try to find the source of the packages, sometimes the providers do a good job. I had such thing with IPSEC. In the end it was a wrong configured device at the other end. Provider contacted their customer and he corrected this.

    Sometimes attacks are simply wrong configured devices and their traffics hit's somewhere ;-)

     

    Best

    Alex 

Children