TechMonkey Posted February 8, 2023 Posted February 8, 2023 Hi all, I don't think there is anything we can do but just wanted to see if the Hive Mind has anything. We are having massive internet issues, sites inaccessible others slow, others fine. The main issue is iSAMS is affected, but it is so random what works and doesn't that it is very tricky doing anything. We have a call open with our ISP, they are saying it is a carrier issue but so far no solution. This has been an issue for 24 hours now. There seems to be no link to what is inaccessible, not the same data center or IP range that we can tell. Any thoughts? To pre-empt the inevitable, yes it probably is DNS. Certainly feels like it.
psydii Posted February 8, 2023 Posted February 8, 2023 I'm told there is something of a ddos happening at the moment? We've had momentary drops of our internet connectivity for the last few days. 1
KK20 Posted February 8, 2023 Posted February 8, 2023 (edited) check your firewall logs, are the requests going out or hanging on the way? pick a machine and check the states of outgoing traffic. Is your IDS taking an unhealthy interest in some of the traffic? Check your IDS logs to see if it is blocking or excessively checking certain destinations. DNS is easy to check, just set one machine to 1.1.1.1 or 8.8.8.8 and let that machine request direct DNS through the firewall Edited February 8, 2023 by KK20 1
SchoolsBroadband Posted February 8, 2023 Posted February 8, 2023 I suspect you're probably right that it is dns. I have heard of a specific provider (no names mentioned) that has had some large ddos issues of late as per @psydii comment. Definitley check your dns preferences and if you are using any forwarders or if there different over your network (we have sometimes seen some clients using statically set dns for historic reasons where as new are via dhcp. Good luck. Dave 1
TechMonkey Posted February 9, 2023 Author Posted February 9, 2023 Thanks everyone. Well unless we are on the provider that is being DDOS and they are keeping quiet about it they are now saying everything is fine. It really makes no sense. I can NSlookup reddit.com, I get two timeouts and then responses. Tracert works. Web traffic does not. We were not working on infrastructure when it stopped working, haven't been for a while. Forwarders all point to external (8.8.8.8 & 1.1.1.1) and DNS on the server NICs are set to internal servers.
SchoolsBroadband Posted February 9, 2023 Posted February 9, 2023 can you constantly ping your server and also the Google DNS servers from your server? If you drop a number of pings that could have an impact. Dave
SchoolsBroadband Posted February 9, 2023 Posted February 9, 2023 perhaps also try statically set DNS on a client machine to be 8.8.8.8 or 1.1.1.1 (don't put in a secondary when testing) and see if that works. If DNS resolutions work fine then you know there's an issue elsewhere and not with connectivity from a client to the internet. Another possibility could be that your server has been hacked and is itself DDoSing destinations on the Internet with a flood of DNS requests. You could be able to see on your firewall how many DNS requests are coming from your server to the general Internet. If its in the thousands then that could be an issue. Thanks Dave 1
TechMonkey Posted February 9, 2023 Author Posted February 9, 2023 Well it looks like we are on the way to being sorted. No idea yet what it was but after "a meeting of the level 3 engineers" it all started working half hour later. Everything is still fragile so I think the ISP is still working on it. I'll leave more info when I know. Thanks for the support all. 1
SchoolsBroadband Posted February 9, 2023 Posted February 9, 2023 I wonder if they blocked outbound and / or inbound dns to the general Internet....
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now