Sonic007 Posted November 11, 2021 Posted November 11, 2021 (edited) Hi everyone, I was wondering if anyone knew what may be causing a problem I am having. The Internet goes down for about 5 minutes several times throughout the day at random times. Every day is different. Internet just stops. Computers show as connected to the network but with no Internet access. A few minutes to 5 minutes later and the internet bounces back to life again. It has been happening for the past few days. No new network equipment added, no changes to servers, nothing different as far as I'm aware! Have tried rebooting our Fibre panel and Mikrotik router and problems still continue to happen. My ISP is looking in to their end but it is taking time and I want to try and figure out if it is their end or ours. Anyone have any ideas? Staff are starting to get annoyed. It isnt the easiest thing to diagnose. Thanks all. Edited November 11, 2021 by Sonic007
Sonic007 Posted November 11, 2021 Author Posted November 11, 2021 Faulty router? Possibly, although it has been working fine and was only installed a couple of months ago.
Sonic007 Posted November 11, 2021 Author Posted November 11, 2021 Any rogue DHCP servers or anything? Not as far as I'm aware. - - - Updated - - - Check your logs for ICMP packets, DDOS?? Where would I go to find this? Thanks.
k9mjl Posted November 11, 2021 Posted November 11, 2021 Firewall logs should give you this information.
sippo Posted November 11, 2021 Posted November 11, 2021 Possibly, although it has been working fine and was only installed a couple of months ago. Don't rule it out. We've had huge issues with those routers in the past. Who's the isp? 1
Sonic007 Posted November 11, 2021 Author Posted November 11, 2021 (edited) Think there may be an IP address issue now but not sure. Several machines connecting to WiFi are now getting a 169 addresses so thinking dhcp issue. I have to manually get it to forget the network to then pull a new valid IP. Hmmm. Edited November 11, 2021 by Sonic007
Sonic007 Posted November 11, 2021 Author Posted November 11, 2021 Those that are connected are fine until the internet stops for a few minutes but then are fine again. New machines connecting are not getting valid dhcp addresses.
3s-gtech Posted November 11, 2021 Posted November 11, 2021 Loop being put in somewhere? Seem a bit too regular for that but could be a loop has been put in and your network is dealing with it haphazardly. 1
robyholmes Posted November 11, 2021 Posted November 11, 2021 I'd check with your ISP as we had DDOS that lasted for around 5 minutes multiple times in the past. It's cheaper to do for such as short time period but you still get the desired effect. 1
Dos_Box Posted November 11, 2021 Posted November 11, 2021 Can I ask if you have WiFi and what type it is as I've had a problem with my home Ruckus AX wifi access point which caused similar problems to yours. A recent firmware update has fixed this. It would prevent all wired connections from connecting to the internet as well. Absoloutely no idea why it created such problems. 1
Michael Posted November 11, 2021 Posted November 11, 2021 If your router is acting as your DHCP Server, it might make sense why some clients are displaying a 169.x address intermittently. It could be an SFP issue at the router/media converter level as a possibility. 1
Sonic007 Posted November 11, 2021 Author Posted November 11, 2021 (edited) Can I ask if you have WiFi and what type it is as I've had a problem with my home Ruckus AX wifi access point which caused similar problems to yours. A recent firmware update has fixed this. It would prevent all wired connections from connecting to the internet as well. Absoloutely no idea why it created such problems. Thanks for your message. Unifi Access Points with on site Key Controller. Edited November 11, 2021 by Sonic007
Sonic007 Posted November 11, 2021 Author Posted November 11, 2021 Thanks for your replies so far. Things seem to have calmed down which is good... yet strange. My iphone abnd a laptop that were picking up a 169 address are now picking up a valid address again. Staff are reporting no 5 minute drop outs since around lunch time. So will see how it goes. I know there were some around 3:30pm - 4pm yesterday and although they arent at the same times day to day I will keep on moitoring things. Bugs me when I cant figure out whats going on. ISP are looking into it and have been "monitoring" the drops in connection but not saying much more. I think on my end things are OK as it would be odd to sometimes get a valid IP and then not wouldnt it? And no idea if thats linked to the drop outs which seem to affect mostly wired users who are already logged on and browsing and then it stops.
Sonic007 Posted November 11, 2021 Author Posted November 11, 2021 If your router is acting as your DHCP Server, it might make sense why some clients are displaying a 169.x address intermittently. It could be an SFP issue at the router/media converter level as a possibility. Router shouldnt be doing any DHCP. Domain Controller handling all that.
jmak Posted November 11, 2021 Posted November 11, 2021 Someone setting up a hotspot with the same SSID and credentials as your genuine network? Lunchtime and just after school makes me suspicious...
Sonic007 Posted November 11, 2021 Author Posted November 11, 2021 Someone setting up a hotspot with the same SSID and credentials as your genuine network? Lunchtime and just after school makes me suspicious... Yesterday it was 11:33, 11:46, 13:04, 4:30, 4:51, and today 09:10, 11:14, and 12:50 I'm going to go on a hunt round the school again and check no one is doing anything. If I find someone is responsable then I will be throwing them off the side of the building.
supportman Posted November 11, 2021 Posted November 11, 2021 First thing I would do is ping a perpetual ping at different points in your network to google.com. Should find out very quickly if its an intenet issue or internal. From exeperience check for loopbacks, students attacking the wifi controller, bad routers. We've had it all over the years 1
Sonic007 Posted November 11, 2021 Author Posted November 11, 2021 Luckily we are a primary school and most students don't know much about I.T. (Yes I know.... famous last words.... and we probably have a kid genius hacker brewing in year5 or something). Will take a closer look and ping.
PaddyNewman Posted November 11, 2021 Posted November 11, 2021 arp -a in CMD when it goes down, does the DC and router have the correct MAC in there. If not, someone connecting to the WiFi with hardcoded DC/Router IP - seen it too many times to not look there. 1
MatthewL Posted November 11, 2021 Posted November 11, 2021 When it happens can you still ping external? Set an external monitor up here, will help you determine where the issue is and see if it drops out of hours too. 1
deathstardan Posted November 12, 2021 Posted November 12, 2021 We've had a similar issue which seems to have calmed down (for now) but we still get the odd random dropout, we've had it last as long as about 10-15 minutes! Turns out it might be something to do with our firewall but our supplier can't seem to find any reason why it's doing so. 1
chazzy2501 Posted November 12, 2021 Posted November 12, 2021 setup a few continuous pings, ping the gateway, ping the dhcp server and ping 8.8.8.8 and when the internet drops see which one starts acting up. Also it may be worth setting up a continuous ping on the switches that sit between them. you may find that 8.8.8.8 still pings when the internet drops in which case it's a DNS issue or a proxy issue. again a big page of black boxes pinging things. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now