The pfSense Store

Author Topic: ntop - Flow Floods  (Read 514 times)

0 Members and 1 Guest are viewing this topic.

Offline TomT

  • Jr. Member
  • **
  • Posts: 99
  • Karma: +1/-0
    • View Profile
ntop - Flow Floods
« on: February 13, 2017, 04:45:36 pm »
Hi

I've noticed a few messages in pfsenses system.log and in ntops alerts stating

Code: [Select]
Host x.x.x.x is possibly under scan attack [65536 active flows]
And then a short while later

Code: [Select]
Host x.x.x.x. is no longer under scan attack [65536 active flows]
Can anyone explain what it means and what I need to do to stop it ?
Thanks

Offline sterlinggold

  • Newbie
  • *
  • Posts: 4
  • Karma: +0/-0
    • View Profile
Re: ntop - Flow Floods
« Reply #1 on: July 23, 2017, 03:51:51 pm »
Seeing the same error. The IP is behind the firewall so this could only be happening from an internal IP, maybe the bridge?
Any possibility to see what source IP triggered this?