[Cialug] Router log issue

Tom Sellers tsellers2009 at gmail.com
Thu Dec 29 13:08:16 CST 2016


I have a netgear router and have noticed lately that I am seeing a number
of entries in the log such as the ones below.

[DoS attack: ACK Scan] attack packets in last 20 sec from ip
[27.151.28.37], Wednesday, Dec 28,2016 21:11:29
[DHCP IP: (192.168.1.78)] to MAC address B8:EE:65:AF:90:64, Wednesday, Dec
28,2016 21:07:33
[DHCP IP: (192.168.1.78)] to MAC address B8:EE:65:AF:90:64, Wednesday, Dec
28,2016 21:07:12
[DHCP IP: (192.168.1.78)] to MAC address B8:EE:65:AF:90:64, Wednesday, Dec
28,2016 21:06:36
[DoS attack: ACK Scan] attack packets in last 20 sec from ip
[27.151.28.37], Wednesday, Dec 28,2016 21:06:14
[DoS attack: ACK Scan] attack packets in last 20 sec from ip
[27.151.28.37], Wednesday, Dec 28,2016 21:05:53
[DoS attack: ACK Scan] attack packets in last 20 sec from ip
[27.151.28.37], Wednesday, Dec 28,2016 21:05:32
[DoS attack: ACK Scan] attack packets in last 20 sec from ip
[27.151.28.37], Wednesday, Dec 28,2016 21:05:10
[DoS attack: ACK Scan] attack packets in last 20 sec from ip
[27.151.28.37], Wednesday, Dec 28,2016 21:04:49

Ignoring the DHCP updates, I am concerned about the many "Dos attack"
messages in the log.  Does anyone have any advice/suggestions concerning
whether or not this is a significant problem that i need to be concerned
about?


More information about the Cialug mailing list