Remove DNS Remove Routers Remove UDP port
article thumbnail

Exploring for Insights on Anomalous Network Traffic

Kentik

To see that, we go back to the Metrics menu and choose Destination » Port. So now we can see that the UDP traffic is being sent to multiple ports, and it’s obvious that we’re experiencing a DNS redirection/amplification attack occurring on port 53, with a lot of port 0 UDP packet fragments being generated as collateral traffic.

Port 40