On 11/07/2014 02:25 AM, Chris Hudson wrote:
This particular device does not have nap server enabled. It's my core router facing my upstream. I have a filter rule to drop port 123 but it isn't curbing the effects. My whole pipe of course is being eaten up. I have currently disabled that interface and am running on my secondary connection. It did this last night from 1 am to 3 am my time and started right at 1 am again today. Also for about 10 to 15 minutes right around 5 pm this evening.
What is the IP that is being attacked? If it is your public IP, you can blackhole that one IP with BGP. Your upstream should be able to tell you the blackhole community to use.
-- Butch Evans 702-537-0979 Network Support and Engineering http://store.wispgear.net/ http://www.butchevans.com/ _______________________________________________ Mikrotik mailing list Mikrotik@mail.butchevans.com http://mail.butchevans.com/mailman/listinfo/mikrotik Visit http://blog.butchevans.com/ for tutorials related to Mikrotik RouterOS