Over the past week we have seen a huge number of 'bots' trying to guess customer email credentials in order to try to send email through our outbound email servers: smtp.aa.net.uk.
The attempts were being blocked due to wrong passwords being used, but this caused significant load on our severs due to all the database lookups involved. To address this, we are blocking IP addresses that are listed on the Spamhaus 'Exploits Blocklist (XBL)' and the Spamhaus 'Combined Spam Sources (CSS)' lists. -These are typically IP address known to have hijacked in some way or known spam senders.
This has reduced the load on the email servers significantly, however we are are still blocking around 1.5 million unique IP addresses each day.
We have had a small number of legitimate customers affected by this as their IP address is on these blocklists. (IPs can be looked up on https://check.spamhaus.org). In these cases, please do contact support and we can discuss workarounds.
Further details as sent out from Draytek:
If you are experiencing this issue, please follow the steps below to troubleshoot:
Disconnect the WAN cable.
Log into the router’s Web UI and check the system uptime. If the uptime is lower than the last known reboot, this indicates the router recently restarted.
Disable Remote Management by going to [System Maintenance] > [Remote Management].
Disable SSL VPN Service by going to [VPN and Remote Access] > [Remote Access Control].
Reboot the router and reconnect the WAN cable.
Monitor the connection to see if the WAN remains stable.
Firmware check and update:
Verify your router’s firmware version. If it is outdated, update it to the latest version.
Before updating, note your current firmware version. If you do not have a copy of the current firmware, download it first.
Take a configuration backup to avoid losing your settings.
If your WAN connection is stable:
Even if your device is not disconnecting, it is good practice to ensure you are on the latest firmware.
If your router is already on recent firmware and the newest version is not marked as Critical, an update may not be urgent but is still recommended for optimal performance and security.
For further assistance, visit our support page or contact our Customer Support team.
Thank you for your patience and cooperation.