Our E1 connection is being closed by our firewall*. It happens intermittently every few days.
I find log entries like this one around the same time as the dropout:
Jun 2 09:53:35 sg580 kernel: Flood - dropped: IN=eth1 OUT= MAC=00:d0:cf:04:7c:13:00:15:2b:ff:97:68:08:00 SRC=61.162.229.252 DST=221.133.***.*** LEN=40 TOS=0x00 PREC=0x00 TTL=104 ID=256 PROTO=TCP SPT=6000 DPT=1433 WINDOW=16384 RES=0x00 SYN URGP=0
Always from the same SRC ip too!
Are we being DOS attacked?!
What can we do about this?
Thanks,
Ashley
*Our firewall is a SnapGear SG580