Jump to content

Recommended Posts

Posted
We (and several local primaries) seem to seeing a lot of outages recently, and according to Virgin ours is due to a ddos type of attack flooding our bandwidthObviously its not something we can do anything about, as its external and Virgin don't seem to have any solution eitherI'm just wondering if any virgin customers are seeing similar issues, its only been happening here in the last few weeks, and its intermittent as well - sometimes nothing for days and then an hour or so of no connection/poor speeds?
Posted (edited)

We had this last year and virgin were no help. Their only solution was to offer someone they deal with which was going to be about 40k pa to help. Problem is less noticable now we have a newer more powerful firewall and or the child that was using a botnet left. We did report it to the cyber crime unit and gave logs of IP address and I urge people to follow up with that. It did take me about half an hour to explain to the local police who they sent as a mesenger in laymans terms what was going on and why having a log on on USB wasn't going to infect the whole of the police network. The police pass the info on to other EU countries (for the moment at least) at least and take action on any UK ip addresses.

 

Edit just checked and we were having UDP floods yesterday at 10:16 and 13:17 from 173.194.5.202 and 216.58.210.33

Edited by Reverend_Dan
  • Thanks 1
Posted
Which firewall are you using? We’ve got the standard virgin router and a smoothwall. You’d think virgin would be able to see our connection being flooded by incoming traffic.
Posted

We have a Fortinet 500D Firewall and filtering, used to have Cisco ASA's that were a seven years old and underpowered. Can not recommend Fortinet enough, They have education pricing, set the rules and done, no messing around, Has app based filtering. Different filtering based on OU or AD Group. A modern firewall makes the job so much easier.

We get hit with stun shells and WP attacks quite a bit on our hosted web servers.

Posted
Cheers, we’ve got a TMG and a smoothwall Utm, but only the utm ip seems be getting hit. As we use that for filtering I have a couple of students I suspect would do something like this!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...