- 论坛徽章:
- 0
|
我的网络拓扑结构:\r\nweb+router(smoothwall)+外部公网(FTTB)\r\n前段时间web服务越来越慢,后来干脆无响应。抓包前,外面已经不能访问我映射出去的web服务,但内部可以管理router。\r\n\r\n在外网卡抓了包,分析了一下:\r\n05:37:32.946164 IP 222.69.201.108.23579 >; myip.http: S 2063669705:2063\r\n669705(0) win 7168 <mss 536,nop,wscale 0,nop,nop,timestamp[|tcp]>;\r\n05:37:32.946748 IP myip.http >; 222.69.201.108.23579: S 1380871688:1380\r\n871688(0) ack 2063669706 win 16616 <mss 1460,nop,wscale 0,nop,nop,timestamp[|tcp\r\n]>;\r\n05:37:35.878949 IP myip.http >; 222.69.201.108.23579: S 1380871688:1380\r\n871688(0) ack 2063669706 win 16616 <mss 1460,nop,wscale 0,nop,nop,timestamp[|tcp\r\n]>;\r\n05:37:35.979529 IP myip.http >; 222.69.201.108.23577: S 1129593690:1129\r\n593690(0) ack 262777394 win 16616 <mss 1460,nop,wscale 0,nop,nop,timestamp[|tcp]\r\n>;\r\n05:37:41.914504 IP myip.http >; 222.69.201.108.23579: S 1380871688:1380\r\n871688(0) ack 2063669706 win 16616 <mss 1460,nop,wscale 0,nop,nop,timestamp[|tcp\r\n]>;\r\n05:37:51.055771 IP 222.69.201.108.23582 >; myip.http: S 3993886453:3993\r\n886453(0) win 7168 <mss 536,nop,wscale 0,nop,nop,timestamp[|tcp]>;\r\n05:37:51.056327 IP myip.http >; 222.69.201.108.23582: S 616408221:61640\r\n8221(0) ack 3993886454 win 16616 <mss 1460,nop,wscale 0,nop,nop,timestamp[|tcp]>;\r\n05:37:53.939357 IP 222.69.201.108.23582 >; myip.http: S 3993886453:3993\r\n886453(0) win 7168 <mss 536,nop,wscale 0,nop,nop,timestamp[|tcp]>;\r\n05:37:53.939810 IP myip.http >; 222.69.201.108.23582: . ack 1 win 16616\r\n <nop,nop,timestamp 1636746 0>;\r\n05:37:53.985651 IP myip.http >; 222.69.201.108.23582: S 616408221:61640\r\n8221(0) ack 3993886454 win 16616 <mss 1460,nop,wscale 0,nop,nop,timestamp[|tcp]>;]\r\n05:37:57.012511 IP 222.69.201.108.23586 >; myip.http: S 2464806837:2464\r\n806837(0) win 7168 <mss 536,nop,wscale 0,nop,nop,timestamp[|tcp]>;\r\n05:37:57.013038 IP myip.http >; 222.69.201.108.23586: S 2195483504:2195\r\n483504(0) ack 2464806838 win 16616 <mss 1460,nop,wscale 0,nop,nop,timestamp[|tcp\r\n]>;\r\n05:37:59.972610 IP myip.http >; 222.69.201.108.23586: . ack 1 win 16616\r\n <nop,nop,timestamp 1636807 0>;\r\n05:38:00.021213 IP myip.http >; 222.69.201.108.23586: S 2195483504:2195\r\n483504(0) ack 2464806838 win 16616 <mss 1460,nop,wscale 0,nop,nop,timestamp[|tcp\r\n]>;\r\n05:38:00.021339 IP myip.http >; 222.69.201.108.23582: S 616408221:61640\r\n8221(0) ack 3993886454 win 16616 <mss 1460,nop,wscale 0,nop,nop,timestamp[|tcp]>;\r\n\r\n\r\n\r\n\r\n\r\n这些是在无法对外提供服务时抓包的数据中提取出来的,在这个过程中,只有这个222.69.201.108地址在访问我的web服务。如果说他是在尝试打开我的web,浏览我的web服务的话,他的频率也太频繁了吧?\r\n然后将其中这个222.69.201.108封掉后,重新认证,dhcp获得的地址竟然没变。而且可以继续向外提供web服务了\r\n\r\n\r\n请帮忙看看,这个是不是syn风暴? |
|