TMG Flood mitigation triggered by connections to *.drip.trouter.io

Hi,

we're frequently seeing alerts like "The number of TCP connections per minute from a specific source IP address exceeded the configured limit". Since our users connect to the proxy from Remote Desktop Servers (Citrix) I've already added those IP's to the Flood mitigation exceptions list and upped the threshold for exceptions.

After investigating a few of these alerts I'm seeing an extremely large amount (over 10.000 per minute) of SSL connections to hosts in the drip.trouter.io domain (ex. 193-149-88-182.drip.trouter.io). This domain seems to belong to Microsoft, does anyone know what is triggering these connections and why? It seems like an unnecessary strain on the TMG servers.

Best regards,

Enrico Klein 

November 14th, 2013 3:35pm

hi,

please block this domain on your TMG and check if there is the error information?

Best Regards

Quan Gu

Free Windows Admin Tool Kit Click here and download it now
November 15th, 2013 9:05am

Hi Quan Gu,

thank you for your reply. I must admit that I'm not very fond of blocking destinations without knowing what they are used for. Since we have thousands of users connecting through our TMG's I cannot foresee the consequences. Especially since the domain is owned by Microsoft Corporation.

Does anyone have any clue as to what this traffic is? TMG categorizes the domain as 'Network Information'

Best regards,

Enrico

November 15th, 2013 12:15pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics