Router detected Large Ping attack and dropped 7 packets.

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Router detected Large Ping attack and dropped 7 packets.

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Router detected Large Ping attack and dropped 7 packets.
Router detected Large Ping attack and dropped 7 packets.
2021-07-09 13:24:24 - last edited 2021-07-09 14:07:38
Model: ER7206 (TL-ER7206)  
Hardware Version: V1
Firmware Version: 1.01

Hello everyone.

 

I have a new network infrastructure running a few days now in a new office under construction.

There I have 3 omada devices (Router, POE Switch and EAP) and a wired security system.

 

Today i added a Win10 laptop for a video conference and i have more than 10 alerts at omada's log like this one: "Router detected Large Ping attack and dropped 7 packets."  

 

The same happened about 1 week before when added the security system in the network, but after it stopped. No other PC or other network device was connected to the network.

 

So is this normal, every time i add a new network device, or it is an attack?

 

Is this critical ? Is this a Ping attack? 

Should i take care of these, or remove these alerts from omada's alert emails ?

 

 

Thanks

 

E.A

  0      
  0      
#1
Options
5 Reply
Re:Router detected Large Ping attack and dropped 7 packets.
2021-07-10 10:56:53

@BravoMike31 have the same. this have to be some sort of a bug, all network clients in my omada network are properly configured and secured but controller alerts on large ping attack all the time (even if WAN is down, so this have to be related to packets exchanged within DMZ).

  0  
  0  
#2
Options
Re:Router detected Large Ping attack and dropped 7 packets.
2021-07-10 14:10:09

@Norbert_123 after my post above, i got more than 15 new emails with the same alerts and today 2-3 times.
 

As i saw there are many other posts with the same issues. It is not normal to have so many ping attacks in a n ew network without PCs running, without a static public ip.

 

TP-Link support must respond! 

  0  
  0  
#3
Options
Re:Router detected Large Ping attack and dropped 7 packets.
2021-07-14 10:15:54

Dear @BravoMike31,

 

BravoMike31 wrote

after my post above, i got more than 15 new emails with the same alerts and today 2-3 times.
 

As i saw there are many other posts with the same issues. It is not normal to have so many ping attacks in a n ew network without PCs running, without a static public ip.

 

Large Ping attack means the gateway receives multiple ping packets larger than 1500 bytes, not only PCs can send ping packets, other network equipment with IP addresses can also have such ability. And I think it's nice to know that the router has detected the Large Ping attacks and blocked them to protect the system from being crashed.

 

If you are curious about where the large ping attack comes from, you may try to capture the ingress & egress packets from the LAN and WAN ports, and check the ICMP packets to trace the attack. In addition, you may need to configure the gateway in Standalone mode and then configure the Port Mirror to capture the packets (the gateway in Controller mode doesn't support the port mirror feature at present).

 

By the way, the email notification for such alerts can be canceled if you don't want to receive them via email.

 

 

Best Regards!
  0  
  0  
#4
Options
Re:Router detected Large Ping attack and dropped 7 packets.
2021-07-14 10:19:18

Dear @Norbert_123,

 

Norbert_123 wrote

@BravoMike31 have the same. this have to be some sort of a bug, all network clients in my omada network are properly configured and secured but controller alerts on large ping attack all the time (even if WAN is down, so this have to be related to packets exchanged within DMZ).

 

The large ping attack is not only coming from the WAN, but also from the LAN.

 

If you disconnect everything from the gateway, do you still get the large ping attack?

Best Regards!
  0  
  0  
#5
Options
Re:Router detected Large Ping attack and dropped 7 packets.
2021-09-15 20:22:47

@Fae 

Please describe (or send a link to a TPLink document/article that details) HOW TO:

  • capture the ingress & egress packets from the LAN and WAN ports, and
  • check the ICMP packets to trace the attack. In addition, you may need to
  • configure the gateway in Standalone mode and then
  • configure the Port Mirror to capture the packets (the gateway in Controller mode doesn't support the port mirror feature at present).

and then...

  • How to reconfigure the gateway (from Standalone mode, back to...Omada controller managed state)

 

I have 1/EA TL-R605 router, 1/EA TL-SG2008-P, 3/EA EAP225 Access Points (2 wired POE, 1 Mesh), 1/EA OC200 Omada controller

Thanks! -Dan

  0  
  0  
#6
Options