My router logs are showing a DoS Fraggle Attack from a 192.168.x.x IP address. The subnet does not match the subnet I’m using. Is this something compromised within my network or an intrusion? Or is it coming from the outside spoofing the 192.168.x.x? Cause for alarm? Any one have experience with this/advice? Lots of other DoS attacks in the log but they are all from outside IP address.
Does the router say which interface the attack came in on? I think that would be the only way to know.
Or mirror the lan port, grab a tcp dump and check for packets that match then repeat on the WAN port.