Zyxel T-56 ping spikes

  • 4 September 2023
  • 43 reacties
  • 1391 Bekeken


Toon eerste reactie

43 reacties

Reputatie 7
Badge +9

Hey @ChaosMonkey, hmm could you run a couple of speedtests for me? Then I will forward this to our tech guys.

The instructions for this can be found on our website. 

Please follow all the steps carefully, please share the screenshots in the topic instead of to our e-mail. We cannot process an application with missing steps.

Reputatie 1

Hey @ChaosMonkey, that's an interesting comparison. I have sent you a new modem just to be sure. Could you test this one out and provide me with feedback?

Hi Tommie, so I did some testing, seems the zyxel does indeed take a knock with the attacks. I can help beta firmware and see if that helps. 
For completeness sake, see the screenshot below. This was taken from my Mikrotik CCR2004 (there is no ways this connection will ever over load this device. 
 

What is a concern and what I would like to draw your attention to, is the fact that I am getting a route change between two IP’s at hope 2 and depending on the path hop 3 as well. now this shouldn’t be happening this frequently, this immediately make me wonder what exactly is going on?

Reputatie 1

Hey @ChaosMonkey , this seems to be a possible denial of service attempt. More people seem to have reported the IP-address 185.191.225.130 as suspect. See for example https://www.abuseipdb.com/check/185.191.225.130 abuseipdb.comabuseipdb.com 185.191.225.130 | Probe Networks | AbuseIPDB 185.191.225.130 has been reported 142 times.

I am not sure how to tackle this issue. This may be an hacker attacking you (do you run a game where bad actors want to attack you?). But as you have a new modem (and a new IP-address) it may be directed to the previous user that had that IP-address. The destination port 8000 could also be the result of a service you have or had had open to the internet (forwarded to an internal server) that people want to disable (see  https://www.speedguide.net/port.php?port=8000 for some examples) SpeedGuideSpeedGuide

Port 8000 (tcp/udp) Port 8000 tcp/udp information, assignments, application use and known security risks. Was this the only message or did you receive more?

Hi @Tommie van Odido , so first off, I don’t have an ports mapped on port 8000. I was getting ping of death logs, and tons of these SYN flood attack logs, even with a new IP. So it’s definitely not targeted at me specifically. Odd thing is, this type of attack is normally not an issue on routers where it will cause a drop in the connection or a spike in CPU usage.


Now I cannot adjust the firewall rules in any meaningful manner, and that is what normally is done to stop this kind of thing. Which would also explain why this wasn’t an issue when I was using the mikrotik, since it would just drop this traffic and be done with it. 


As to why port 8000 shows up, that is something for Odido to address, since that isn’t something I configured nor can see that it is open. The games I play that might open a port with uPnP, but they don’t use port 8000, they either use a port in the 300-400 range, or in the 27k range. 

It is puzzling why it would lead to the device dropping the WAN connection.

Reputatie 7
Badge +9

Hey @ChaosMonkey , this seems to be a possible denial of service attempt. More people seem to have reported the IP-address 185.191.225.130 as suspect. See for example https://www.abuseipdb.com/check/185.191.225.130 abuseipdb.comabuseipdb.com 185.191.225.130 | Probe Networks | AbuseIPDB 185.191.225.130 has been reported 142 times.

I am not sure how to tackle this issue. This may be an hacker attacking you (do you run a game where bad actors want to attack you?). But as you have a new modem (and a new IP-address) it may be directed to the previous user that had that IP-address. The destination port 8000 could also be the result of a service you have or had had open to the internet (forwarded to an internal server) that people want to disable (see  https://www.speedguide.net/port.php?port=8000 for some examples) SpeedGuideSpeedGuide

Port 8000 (tcp/udp) Port 8000 tcp/udp information, assignments, application use and known security risks. Was this the only message or did you receive more?

Reputatie 1

Hey @ChaosMonkey, that's an interesting comparison. I have sent you a new modem just to be sure. Could you test this one out and provide me with feedback?

Hi Tommie, 

Got the new modem, just in time as well, the old one actually stopped getting an IP address on it’s WAN port, meaning I had no internet. Even after resetting it and a call with support it just stopped working. 

 

At least the new modem immediately got an IP address. So far so good. Even my internet speeds are better. 
I did pick up times where I was getting ping spikes, however the logs of the new modem revealed this 
102.611585] SYN_FLOODING ATTACK:IN=eth1.3 OUT= MAC=10:71:b3:a1:dc:bd:00:0e:00:00:00:04:08:00 SRC=185.191.225.130 DST=<IP> LEN=60 TOS=0x00 PREC=0x00 TTL=58 ID=1016 DF PROTO=TCP SPT=35387 DPT=8000 WINDOW=64240 RES=0x00 SYN URGP=0 

This actually caused the modem to drop my internet connection. 

Reputatie 1

Hey @ChaosMonkey, that's an interesting comparison. I have sent you a new modem just to be sure. Could you test this one out and provide me with feedback?

Will do. 

 

Also there seems to be something unstable happening in the routing. 
 

hop 2 and 3 show route changes, so I am getting unstable latencies 

Reputatie 7
Badge +9

Hey @ChaosMonkey, that's an interesting comparison. I have sent you a new modem just to be sure. Could you test this one out and provide me with feedback?

Reputatie 1

For comparison, I used my own router, so just swapped out the Zyxel for a mikrotik hex (and it’s not even as powerful.) 

Fyi I connect to the Zyxel over a 2.5Gbps connection. 
 

Here is what it looks like using the mikrotik

 

 

So it looks like the custom firmware that is on the Zyxel from Odido(T-Mobile) could be the cause. 

  1.  Can I ask for a replacement router?
  2. Can I beta test new firmware?

 

Reputatie 7
Badge +9

@ChaosMonkey, at the moment, I am not leaving or ruling anything out. The modem could possibly be a cause. I just want to hold out for another look from our Superusers! 

Reputatie 1

Hi @ChaosMonkey, thanks for all the screenshots. I would like to ask if @TMTV and @louisL would like to assist you with the settings. I am also curious if they can see anything else in the screenshots with their expert eye.  

Hi, one thing that seems to stand out to me, is that the average response time of the modem seems to be an issue. Which could explain the odd avg’s seen in the pings to the google and cloudflare. If ICMP was being throttled that could explain it, but the network isn’t busy and a TCP ping rules that out. Seems the modem or the custom firmware T-Mobile (Odido) puts on this Zyxel might have an issue?

Reputatie 7
Badge +9

Hi @ChaosMonkey, thanks for all the screenshots. I would like to ask if @TMTV and @louisL would like to assist you with the settings. I am also curious if they can see anything else in the screenshots with their expert eye.  

Reputatie 1

Hey @ChaosMonkey, can you take a screenshot of the results instead of the hops? Also, I would like to ask you to make a sketch of your home network. What we suggest is ONT/Media Converter -> Zyxel -> Wired connection laptop/other device. I am very curious to know what else is in between.

I do have it as ONT → Zyxel → Wired connection.
There is nothing between the ONT and the Zyxel. 

 

I have made a diagram of my network. I have done the tests from both my PC and the orange pi (see diagram, that is directly connected to the Zyxel) and it doesn’t change. I am questioning this Zyxel because of the spikes to it. I haven’t seen for example at a previous ISP my Mikrotik (ISP supplied router) do this. 

Even if I unplug everything like I did in the previous results and have just my PC connected directly to the Zyxel do I see the exact same behaviour. 
 


From the PC
TCP ping to google.com


From the orange pi 
 

I have an openwrt router I can also test with , I just need to know what IPoE settings to use? 

Reputatie 7
Badge +9

Hey @ChaosMonkey, can you take a screenshot of the results instead of the hops? Also, I would like to ask you to make a sketch of your home network. What we suggest is ONT/Media Converter -> Zyxel -> Wired connection laptop/other device. I am very curious to know what else is in between.

Reputatie 1

Hey @ChaosMonkey, welcome to our Community!

Good that you are sounding the alarm for this. I immediately went to check for you and I see that you have your own router/switch connected. Could you run these two commands if you have unplugged everything and are only connected directly wired to your laptop/desktop? Ping -n 50 1.1.1.1 & Ping -n 50 8.8.8.8 in CMD. Do this with only the Zyxel modem connected to your network with a wired connection. Suppose you have a VPN, disable it too.

What do you mean you can see I have my own router/switch connected? The tests I showed was done from a linux machine directly connected to the Zyxel router. Even with just my PC connected it still shows odd spikes, and I was initially talking about ping spikes to the Zyxel router itself. That is why my concern is sitting 
 

 

Reputatie 7
Badge +9

Hey @ChaosMonkey, welcome to our Community!

Good that you are sounding the alarm for this. I immediately went to check for you and I see that you have your own router/switch connected. Could you run these two commands if you have unplugged everything and are only connected directly wired to your laptop/desktop? Ping -n 50 1.1.1.1 & Ping -n 50 8.8.8.8 in CMD. Do this with only the Zyxel modem connected to your network with a wired connection. Suppose you have a VPN, disable it too.

Reputatie 1

Hi @ChaosMonkey 

Did you use a wired connection between your test device and the router? Wifi is unreliable for such test.

Yeah, you can see that from the first ping, the sub ms ping is normally not achievable on wifi. 
I am wired in with all my devices except my phone. 

Reputatie 7
Badge +14

Hi @ChaosMonkey 

Did you use a wired connection between your test device and the router? Wifi is unreliable for such test.

Reputatie 1

Seems it is based on the EX5601/EX5600-T SERIES 

Reageer