Hello,
last time we experience a lot of udp flood from Google servers to a random port on the untrust / wan interface.
Any ideas what can cause this problem? Can i generally block incomig udp 443 traffic on the untrust interface?
2016-04-20 10:41:28 alert UDP flood! From 195.49.27.205:443 to 212.59.141.68:23823, proto UDP (zone Untrust, int ethernet0/2). Occurred 2 times.
2016-04-20 10:41:27 alert UDP flood! From 195.49.27.205:443 to 212.59.141.68:23823, proto UDP (zone Untrust, int ethernet0/2). Occurred 111 times.
2016-04-20 10:40:44 alert UDP flood! From 195.49.27.205:443 to 212.59.141.68:23823, proto UDP (zone Untrust, int ethernet0/2). Occurred 2 times.
2016-04-20 10:40:43 alert UDP flood! From 195.49.27.205:443 to 212.59.141.68:23823, proto UDP (zone Untrust, int ethernet0/2). Occurred 67 times.
2016-04-20 10:01:45 alert UDP flood! From 172.217.19.14:443 to 212.59.141.68:12851, proto UDP (zone Untrust, int ethernet0/2). Occurred 4 times.
2016-04-20 10:01:44 alert UDP flood! From 172.217.19.14:443 to 212.59.141.68:12851, proto UDP (zone Untrust, int ethernet0/2). Occurred 68 times.