OPNsense Forum

Archive => 22.7 Legacy Series => Topic started by: xur17 on December 01, 2022, 02:50:19 am

Title: Router Crash + High Volume DNS Issue
Post by: xur17 on December 01, 2022, 02:50:19 am
I've been using an OPNSense router running OPNsense 22.7.8-amd64 with a J4125 cpu for several months now with 0 issues. Today my phone dropped a voip call, and when checking on my other computers, my entire network had stopped working (could not access router web interface, could not resolve dns (unbound), could not ping 8.8.8.8 ).

After rebooting the router, I was able to use the internet, but was getting slow / timed out responses from my local DNS server (I use unbound). 10 minutes later or so I restarted my router again, and everything seemed to be working fine.

When looking at my netflow logs, I noticed that my wan traffic went to 0 during this time period while my lan traffic spiked. When digging into my netflow logs, I see close to 20gb of dns traffic from one of the computers on my network to my router (a server, not the computer I mentioned above).

Has anyone run into something like this or have suggestions on where to start looking? I can't figure out if my router crashed, causing this internal computer to generate a bunch of traffic, or if it was the other way around (internal computer DoS-ed unbound, which brought the network down).