Detected TCP SYN packets attack Since Firmware update to for ER8411 (1.2.0) and ER6505 (2.2.3)

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Detected TCP SYN packets attack Since Firmware update to for ER8411 (1.2.0) and ER6505 (2.2.3)

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Detected TCP SYN packets attack Since Firmware update to for ER8411 (1.2.0) and ER6505 (2.2.3)
Detected TCP SYN packets attack Since Firmware update to for ER8411 (1.2.0) and ER6505 (2.2.3)
2024-01-02 10:12:46 - last edited 2024-01-04 09:59:04
Model: ER8411   ER605 (TL-R605)  
Hardware Version: V1
Firmware Version: 1.2.0 Build 20231214 Rel.77035

Hello, 

 

yesterday we have update all our switches and routers. Since the update we get every 10 minutes the message with: 

 

Detected TCP SYN packets attack and dropped 138 packets.

 

Update has been done at 00:30 CET therefore since this time we have get a lot of messages. The problem is that no more information is given this means we can not understand ist this a local device or an attack from outside. Is there any possible way to find the issue, device etc. which is responsible for this attacks?

 

Many thanks in advanced! 

 

  1      
  1      
#1
Options
1 Accepted Solution
Re:Detected TCP SYN packets attack Since Firmware update to for ER8411 (1.2.0) and ER6505 (2.2.3)-Solution
2024-01-04 09:58:59 - last edited 2024-01-04 09:59:04

Hi @Cij@Cotchet 

Thanks for posting in our business forum.

Here's the fix.

https://community.tp-link.com/en/business/forum/topic/636216?replyId=1300898

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
Recommended Solution
  0  
  0  
#3
Options
5 Reply
Re:Detected TCP SYN packets attack Since Firmware update to for ER8411 (1.2.0) and ER6505 (2.2.3)
2024-01-04 08:00:22

  @Cij Up, I have the same issue since update ER8411 in 1.2.0

  0  
  0  
#2
Options
Re:Detected TCP SYN packets attack Since Firmware update to for ER8411 (1.2.0) and ER6505 (2.2.3)-Solution
2024-01-04 09:58:59 - last edited 2024-01-04 09:59:04

Hi @Cij@Cotchet 

Thanks for posting in our business forum.

Here's the fix.

https://community.tp-link.com/en/business/forum/topic/636216?replyId=1300898

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
Recommended Solution
  0  
  0  
#3
Options
Re:Detected TCP SYN packets attack Since Firmware update to for ER8411 (1.2.0) and ER6505 (2.2.3)
2024-01-04 10:31:13

  @Clive_A  Thanks for your suggestion. I have already see this solutions but at the moment i'm trying to decide whether this affects safety. Opinions differ widely here too. Do you have an opinion on this? Is this setting /block new with the last upgrade or why I geting the message now and not before?

 

Maybe TP-Link can add a option to the notification section to activate or deactivate notification for this kind of attacks? 

 

Thanks

  0  
  0  
#4
Options
Re:Detected TCP SYN packets attack Since Firmware update to for ER8411 (1.2.0) and ER6505 (2.2.3)
2024-01-05 06:25:22

  @Clive_A 

I would also be interested to know whether this does not affect safety. Am I deactivating a security function just so that I no longer receive a notification? Do I understand that correctly?

Thank you very much

  1  
  1  
#5
Options
Re:Detected TCP SYN packets attack Since Firmware update to for ER8411 (1.2.0) and ER6505 (2.2.3)
2024-01-05 06:42:02

Hi @Tpexe 

Thanks for posting in our business forum.

Tpexe wrote

  @Clive_A 

I would also be interested to know whether this does not affect safety. Am I deactivating a security function just so that I no longer receive a notification? Do I understand that correctly?

Thank you very much

You might find this article helpful.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  1  
  1  
#6
Options