Define this network behavior
traceroute: Warning: www.google.com has multiple addresses; using 208.67.219.231
+traceroute to google.navigation.opendns.com (208.67.219.231), 64 hops max, 40 byte packets+
+1 192.168.1.1 (192.168.1.1) 0.959 ms 0.658 ms 0.653 ms+
+2 cpe-76-95-80-1.socal.res.rr.com (76.95.80.1) 12.597 ms 12.703 ms 8.229 ms+
+3 24.24.193.145 (24.24.193.145) 13.410 ms 12.509 ms 12.428 ms+
+4 ae5-chswca1-rtr2.socal.rr.com (66.75.145.28) 12.896 ms 14.031 ms 13.275 ms+
+5 ge-4-3-0.tustca1-rtr1.socal.rr.com (66.75.145.13) 15.249 ms 15.197 ms 14.844 ms+
+6 ae-5-0.cr0.lax30.tbone.rr.com (66.109.6.64) 19.756 ms 36.849 ms 68.577 ms+
+7 ae-1-0.pr0.lax10.tbone.rr.com (66.109.6.131) 17.338 ms 17.727 ms 18.051 ms+
+8 * * *+
+9 te8-1.ccr01.lax01.atlas.cogentco.com (154.54.0.213) 31.040 ms te4-2.ccr01.lax01.atlas.cogentco.com (154.54.6.229) 18.951 ms te7-4.ccr01.lax01.atlas.cogentco.com (154.54.3.9) 89.567 ms+
+10 te3-1.ccr02.sjc01.atlas.cogentco.com (154.54.5.185) 28.293 ms 29.853 ms te9-3.ccr02.sjc01.atlas.cogentco.com (154.54.25.186) 28.882 ms+
+11 te7-2.ccr02.sjc03.atlas.cogentco.com (66.28.4.78) 42.413 ms 29.635 ms 28.248 ms+
+12 te9-3.mpd01.sjc04.atlas.cogentco.com (154.54.0.170) 29.837 ms te4-3.mpd01.sjc04.atlas.cogentco.com (154.54.24.141) 29.947 ms te9-3.mpd01.sjc04.atlas.cogentco.com (154.54.0.170) 29.393 ms+
+13 38.104.140.46 (38.104.140.46) 30.549 ms 31.876 ms 32.086 ms+
The problem lays at hop 8 between
ae-1-0.pr0.lax10.tbone.rr.com
and
te8-1.ccr01.lax01.atlas.cogentco.com
This problem has been persistant for at least one week.
Later in my firewall log I discovered a large number of stealth mode connection attempts paired with nmblookup querys all pointing to IP 38.118.213.10.
Whois shows 38.118.213.10 as belonging to atlas.cogentco.com.
So I'm having peering problems with atlas.cogentco.com, and I am also being attacked by someone or something over there?
iMac 2.4 GHz Intel Core 2 Duo, 4 GB RAM, Mac OS X (10.5.7), Bootcamp 50 GB Windows 7
