| |
| Problem in Maidenhead - affecting VoIp/ethernet/email/etc - Closed |
26 Jan 2012 13:10:00 |
Details 24 Jan 2012 21:16:14 |
We are seeing a major issue in Midenhead - high levels of transit packet loss that will be affecting VoIP, email, and Ethernet customers (as well out our offices). |
Update
24 Jan 2012 21:47:11
|
Looking like some sort of denial of service attack.
|
Update
24 Jan 2012 22:34:04
|
Sorry for the delay posting more details. This affects our links directly and making it difficult. The problem appears to be a huge denial of service attack invovling tens of thousands of sessions and filling gigabit links.
We have identified the target and disconnected it, black holed the target and even tried to divert traffic but to no avail as yet.
We are still working on this.
|
Update
24 Jan 2012 23:03:38
|
Just an update to say that this is still being worked on...
|
Update
24 Jan 2012 23:23:30
|
Still working on this
|
Update
24 Jan 2012 23:28:57
|
The problem is now only affeting Ethernet customers on the same block as the address being DDOS'd. We are still working on the issue. Most other services will be working fine now.
|
Update
24 Jan 2012 23:57:55
|
Some side effects on other services from Maidenhead, but we are still working on narrowing down the issue.
|
Update
25 Jan 2012 00:01:48
|
DOS attacks are, thankfully, rare. This has to be the biggest we have seen.
We will, of course, be talking to the customer who is being DOSed to fine what could have provoked such a major attack. There is usually a reason.
|
Update
25 Jan 2012 13:20:48
|
The blackhole for the target machine was removed at 1pm today, however the traffic was still being sent and affected VoIP, email and Ethernet services.
The block is now in place again, and we'll continue to investigate.
|
| Started |
24 Jan 2012 21:00:00 |
| Closed: |
26 Jan 2012 13:10:00 |
|
|