2015-02-24 17:49 GMT-03:00 Ciro Iriarte <cyru...@gmail.com>: > Hi!, I'm seeing a lot of messages of type "Timeout from remote TCP client > 10.XXX.XXX.XXX", it seems to be an attack given we have "any-to-tcp = yes". > > Is this usual?, is there anyway to identify the attackers?. The service is > working fine and we have in our roadmap constant packed capture for data > mining but I find this behaviour new/interesting today :) > > Any comments? > > Regards, > > -- > Ciro Iriarte > http://iriarte.it > -- >
Well, never mind. After all, those are legitimate clients and there seems to be a firewall with connection tracking issues. What's unexpected to me is having TCP requests, I was expecting only UDP traffic from end users. Regards, -- Ciro Iriarte http://iriarte.it --
_______________________________________________ Pdns-users mailing list Pdns-users@mailman.powerdns.com http://mailman.powerdns.com/mailman/listinfo/pdns-users