Teamspeak Server > Clients drop randomly

Hey everyone,

Since a few weeks I have clients random dropping out of my own Teamspeak server.
I checked with the VPS provider and they confirmed there was no outage at that point in time. Weird is that it affects random users.
2 days go, 2 users disconnected at the same time and connected back in instantly.

Anyone else experiencing this?

Log:

2020-05-10 13:52:12.925167|INFO    |PktHandler    |1  |Dropping client 447 because of ping timeout 19 0 0
2020-05-10 13:52:12.925789|INFO    |PktHandler    |1  |Dropping client 446 because of ping timeout 19 0 0
2020-05-10 13:52:12.926322|INFO    |PktHandler    |1  |Dropping client 445 because of ping timeout 19 0 0
2020-05-10 13:52:12.926150|INFO    |VirtualServerBase|1  |client disconnected 'Vliet'(id:3156) reason 'reasonmsg=connection lost'
2020-05-10 13:52:12.927911|INFO    |VirtualServerBase|1  |client disconnected 'jpdsc'(id:3115) reason 'reasonmsg=connection lost'
2020-05-10 13:52:12.928302|INFO    |PktHandler    |1  |Dropping client 444 because of ping timeout 19 0 0
2020-05-10 13:52:12.929378|INFO    |PktHandler    |1  |Dropping client 443 because of ping timeout 19 0 0
2020-05-10 13:52:12.929145|INFO    |VirtualServerBase|1  |client disconnected 'RPDSC'(id:3155) reason 'reasonmsg=connection lost'
2020-05-10 13:52:12.933286|INFO    |VirtualServerBase|1  |client disconnected 'Quak'(id:2691) reason 'reasonmsg=connection lost'
2020-05-10 13:52:12.934072|INFO    |VirtualServerBase|1  |client disconnected 'yorrick1991'(id:2999) reason 'reasonmsg=connection lost'

Going to try and narrow it down to a possible random DDOS attack.
Changed the DNS settings and removed the @ and WWW from the DNS, only adding ts.domain.com. If this fixed the issue than it was a possible DNS scanner

Thanks!

Are the affected users randomly in the same location or share the same provider? having the same IP address block? Please check if they have similarities on their IP addresses.

Otherwise take a look into the server… maybe a weak (D)DoS attack or something else, a big inbound/ingoing of packets or something else in this area.

I don’t think that the teamspeak server does have any relations with this.

1 Like

Thanks for the reply.
All clients who dropped come from different countries actually.

I checked the VPS logs for inbound/outbound traffic and there is nothing unusual, it is using minimal the last 2 weeks.