user_u6dx3g's profile

Contributor

 • 

34 Messages

Saturday, January 9th, 2021 6:00 PM

Closed

DoS Attack ???

I was experiencing random dropoffs on some websites only. The connection would be up and fine and I can browse and everything but some websites woudl just stop working. I started looking into it and noticed that exact at that time these DoS Attack messages were there in the router log.

Its a NG C7000 V2. and the dos attack prevention option is On. 

Is this something to be concerned about ? Is that 75.75.75..... ip the comcast dns ? whats goin on here ? Please advise.

 

[DoS attack: TCP- or UDP-based Port Scan] from 75.75.75.75, port 53

DoS attack: TCP- or UDP-based Port Scan] from 75.75.76.76, port 53

[DoS attack: TCP- or UDP-based Port Scan] from 75.75.75.75, port 53

[DoS attack: SYN Flood] from 13.68.247.210, port 443

[DoS attack: SYN Flood] from 35.166.131.228, port 443

[DoS attack: SYN Flood] from 44.233.3.2, port 443

[DoS attack: SYN Flood] from 151.101.42.49, port 443

[DoS attack: SYN Flood] from 104.214.58.194, port 443

 

Expert

 • 

110K Messages

4 years ago

No. That is regular Comcast DNS server queries / traffic on DNS port 53. Your firewall is being a hypochondriac in its announcements. It is doing its job.

Contributor

 • 

34 Messages

4 years ago

Ok. Couple of questions -

Would the router/firewall then disable or halt any traffic ? because thats what seems to be happening, although not all traffic.

Has anything changed recently with comcast dns ? Never had this problem before, except in the last 3-4 weeks.

Expert

 • 

110K Messages

4 years ago

Not any traffic that is allowed by your firewall rules or any traffic that is first initiated from inside your LAN. Only unsolicited traffic from the WAN / internet. This is a basic description.

Contributor

 • 

34 Messages

4 years ago

Why is there incoming traffic from dns ? Shouldn't it be just outgoing ?

Visitor

 • 

1 Message

4 years ago

I am using a Netgear router connected to Xfinity modem in bridge mode.

Every morning my system is disconnected.

Netgear support says I am getting DoS attacks from Xfinity.   this is from the log today:

DoS attack: FIN Scan] attack packets in last 20 sec from ip [34.120.85.253], Monday, Jul 12,2021 07:07:16

How can I stop this?

Expert

 • 

110K Messages

@Happyjack52

Please create a new topic of your own here on this board detailing your issue (copy your post and paste it there). Thanks. Re-closing this 6-month-old dead thread that was improperly re-opened by the new forum software / platform. A known issue that is being worked on.

 

I am not a Comcast Employee.
I am a Customer Expert volunteering my time to help other customers here in the Forums.
We ask that you post publicly so people with similar questions may benefit from the conversation.

Was your question answered? Please mark an Accepted Answer!tick
I am not a Comcast Employee.
I am a Customer Expert volunteering my time to help other customers here in the Forums.
We ask that you post publicly so people with similar questions may benefit from the conversation.

Was your question answered? Please mark an Accepted Answer!tick
I am not a Comcast Employee.
I am a Customer Expert volunteering my time to help other customers here in the Forums.
We ask that you post publicly so people with similar questions may benefit from the conversation.

Was your question answered? Please mark an Accepted Answer!tick
forum icon

New to the Community?

Start Here