QUOTE (Tim Igoe @ Apr 15 2008, 11:23 AM)

Currently noticing a LOT of connections in SYN_WAIT or SYN_RECV status all from the same IP address, 208.98.15.24.
This might not seem odd on its own, but connections are showing on all of our servers, which are (as far as I understand) located in different data centers, and all with very different IP addresses, hosting different sites. Our IP's are definately not consecutive so its not that the person is hitting X and X+1 etc, perhaps hitting a larger block than just us?
Theres literally hundreds of connections between all the servers.
Anyone else noticing this at the moment?
Our servers IP's are in the 67.15.7*.* range and in the 67.19.47.* range
Yes. I was looking at another issue when I noticed it. When I look at netstat I see thousands of connections from 208.98.15.24:34757 SYN_RECV. I alerted our ISP but have not heard from them. I did a tracerout on that and also had an ending in the 10.10 and 10.0 territory.
traceroute to 208.98.15.24 (208.98.15.24), 30 hops max, 40 byte packets
1 72.20.155.1 (72.20.155.1) 2.003 ms 1.74 ms 1.871 ms
2 ge-1-6.r04.hstntx01.us.bb.gin.ntt.net (128.241.5.1) 2.284 ms 2.299 ms 2.593 ms
3 xe-1-3-0.r20.hstntx01.us.bb.gin.ntt.net (129.250.4.233) 2.648 ms 2.514 ms 2.466 ms
4 as-0.r20.dllstx09.us.bb.gin.ntt.net (129.250.3.129) 9.969 ms 9.866 ms 10.436 ms
5 ae-0.r21.dllstx09.us.bb.gin.ntt.net (129.250.2.59) 10.001 ms 12.543 ms 12.346 ms
6 p64-1-1-0.r21.chcgil09.us.bb.gin.ntt.net (129.250.2.23) 36.51 ms 36.63 ms 36.581 ms
7 xe-3-3.r00.chcgil09.us.bb.gin.ntt.net (129.250.3.222) 36.439 ms 36.332 ms 36.577 ms
8 66.90.127.209 (66.90.127.209) 36.904 ms 36.731 ms 36.829 ms
9 (66.90.127.178) 34.41 ms 34.485 ms 34.391 ms
10 10.10.50.2 (10.10.50.2) 36.671 ms 36.711 ms 31.776 ms
11 10.0.0.6 (10.0.0.6) 34.466 ms 34.576 ms 34.181 ms
12 * * *
13 208.98.15.24 (208.98.15.24) 31.818 ms 34.197 ms 32.019 ms
What's up with that?