Jump to content

Recommended Posts

Posted

Hi all,

I don't think there is anything we can do but just wanted to see if the Hive Mind has anything.

 

We are having massive internet issues, sites inaccessible others slow, others fine. The main issue is iSAMS is affected, but it is so random what works and doesn't that it is very tricky doing anything. We have a call open with our ISP, they are saying it is a carrier issue but so far no solution. This has been an issue for 24 hours now. There seems to be no link to what is inaccessible, not the same data center or IP range that we can tell.

 

Any thoughts?

 

To pre-empt the inevitable, yes it probably is DNS. Certainly feels like it.

Posted
I'm told there is something of a ddos happening at the moment? We've had momentary drops of our internet connectivity for the last few days.
  • Thanks 1
Posted (edited)
check your firewall logs, are the requests going out or hanging on the way? pick a machine and check the states of outgoing traffic. Is your IDS taking an unhealthy interest in some of the traffic? Check your IDS logs to see if it is blocking or excessively checking certain destinations. DNS is easy to check, just set one machine to 1.1.1.1 or 8.8.8.8 and let that machine request direct DNS through the firewall Edited by KK20
  • Thanks 1
Posted

I suspect you're probably right that it is dns.

 

I have heard of a specific provider (no names mentioned) that has had some large ddos issues of late as per @psydii comment.

 

Definitley check your dns preferences and if you are using any forwarders or if there different over your network (we have sometimes seen some clients using statically set dns for historic reasons where as new are via dhcp.

 

Good luck.

 

Dave

  • Thanks 1
Posted

Thanks everyone. Well unless we are on the provider that is being DDOS and they are keeping quiet about it they are now saying everything is fine.

It really makes no sense.

I can NSlookup reddit.com, I get two timeouts and then responses. Tracert works. Web traffic does not.

We were not working on infrastructure when it stopped working, haven't been for a while.

 

Forwarders all point to external (8.8.8.8 & 1.1.1.1) and DNS on the server NICs are set to internal servers.

Posted

perhaps also try statically set DNS on a client machine to be 8.8.8.8 or 1.1.1.1 (don't put in a secondary when testing) and see if that works. If DNS resolutions work fine then you know there's an issue elsewhere and not with connectivity from a client to the internet.

 

Another possibility could be that your server has been hacked and is itself DDoSing destinations on the Internet with a flood of DNS requests. You could be able to see on your firewall how many DNS requests are coming from your server to the general Internet. If its in the thousands then that could be an issue.

 

Thanks

 

Dave

  • Thanks 1
Posted

Well it looks like we are on the way to being sorted. No idea yet what it was but after "a meeting of the level 3 engineers" it all started working half hour later. Everything is still fragile so I think the ISP is still working on it. I'll leave more info when I know.

 

Thanks for the support all.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...