Hello,
We have an IPCOP box with two Zones, GREEN and RED. The RED interface has an Public IP address and connects directly to a router and out to the Internet. The GREEN interface connects back in to the Local Network. RED IF has port forwarding rules to facilitate core services in the LAN such as Email, VPN, Mobility etc. The GREEN zone has unrestricted access out to the RED zone. Please see attached code snipplet for an (allbeit poor) attempt to draw the network.
The problem we are getting is the pipe out to the Internet is getting flooded with traffic on very regular intervals. When such a surge in traffic occurs extrernal response times to 203.42.x.x sit between 2500-3500ms or simply time out. Of course due to this our core services (VPN, EMAIL) stop working.
Please view attached pictures for the traffic graphs in IPCOP.
GREEN
Traffic is spiking roughly every 2 hours lasting for about an hour. The traffic is incoming on GREEN.
RED
Outbound traffic on RED is corresponding directly with inbound traffic on GREEN.
This has been happening for about 4 days now but is not the first time it has happened. Unless I am reading it wrong the traffic is being generated from inside our network and could possibly be due to a workstation being 'owned'.
If anyone could suggest steps I can take to find the source of the problem and fix I would be most appreciative. I am able to run tcpdump on the IPCOP box but have only ever run this once so if possible provide syntax.
Thanks
Start Free Trial