Hello,
First off, please excuse my complete inexperience in these matters. Everything I know, (not being that much) is self taught so there are large gaps.
I own and collocate a dedicated server in the UK. Mainly I use the server for VOIP and a few game servers. Recently, the server has been under what is best described as a very small DOS attack. Its not quite blocking up the connection entirely, but it is causing intermittent lag spikes and occasionally complete loss of connection.
With nothing running on the server at all, there is a constant .20-.30% network usage with spikes of up to 2.50% (this is on a 100Mbps connection)
To find out what this mystery network usage could be, I installed the Microsoft's Network Monitor 3.4 and I found several culprits. Below is an image from the network monitor.
As you can see from the image above, the following IPs are sending about 200~ each per second.
208.43.236.122/6
21.34.158.1
89.238.144.11
Some of the requests are using the HTTP protocol and seem to be targeting Call of Duty server ports (28960/5)
I have no use for HTTP on my server, so the first thing I did was to try and block port 80 through the windows firewall. This had no affect
Then I tried to block the individual IPs through the windows firewall, but again with no success. They still showed up in the network monitor even though they were supposedly blocked by the firewall.
However, to block an IP through the windows firewall, I selected the option for "All Programs" even though in the Network Monitor, there is nothing in the "Process Name" column. Could this be the reason that it is not working? (link to the guide I used to block the IP: https://support.gearhost.com/KB/a520/block-ip-address-with-windows-firewall-2008.aspx )
I also tried banning the IPs through IPSec but again to no avail. (link to the guide I used: http://forums.webhostautomation.com/showthread.php?t=2906&page=1 )
I apologise for the long post! I wanted to make sure there was a much information as possible, and I am at my wits end with this problem! Any help would be greatly appreciated!
Walker
First off, please excuse my complete inexperience in these matters. Everything I know, (not being that much) is self taught so there are large gaps.
I own and collocate a dedicated server in the UK. Mainly I use the server for VOIP and a few game servers. Recently, the server has been under what is best described as a very small DOS attack. Its not quite blocking up the connection entirely, but it is causing intermittent lag spikes and occasionally complete loss of connection.
With nothing running on the server at all, there is a constant .20-.30% network usage with spikes of up to 2.50% (this is on a 100Mbps connection)
To find out what this mystery network usage could be, I installed the Microsoft's Network Monitor 3.4 and I found several culprits. Below is an image from the network monitor.
As you can see from the image above, the following IPs are sending about 200~ each per second.
208.43.236.122/6
21.34.158.1
89.238.144.11
Some of the requests are using the HTTP protocol and seem to be targeting Call of Duty server ports (28960/5)
I have no use for HTTP on my server, so the first thing I did was to try and block port 80 through the windows firewall. This had no affect
Then I tried to block the individual IPs through the windows firewall, but again with no success. They still showed up in the network monitor even though they were supposedly blocked by the firewall.
However, to block an IP through the windows firewall, I selected the option for "All Programs" even though in the Network Monitor, there is nothing in the "Process Name" column. Could this be the reason that it is not working? (link to the guide I used to block the IP: https://support.gearhost.com/KB/a520/block-ip-address-with-windows-firewall-2008.aspx )
I also tried banning the IPs through IPSec but again to no avail. (link to the guide I used: http://forums.webhostautomation.com/showthread.php?t=2906&page=1 )
I apologise for the long post! I wanted to make sure there was a much information as possible, and I am at my wits end with this problem! Any help would be greatly appreciated!
Walker
Last edited by a moderator: