Настроить внешний сервер пока не могу - некогда. Просто пользователи рвут на части. Выкладываю логи, которые зафиксировал д-линк за последние несколько минут, когда все работает и стихли звонки от юзеров.
[2005-07-06 12:57:57] <5>EFW: CONN: prio=2 rule=Rule_6 conn=open connipproto=TCP connrecvif=LAN connsrcip=192.168.1.16 connsrcport=4152 conndestif=core conndestip=192.168.1.1 conndestport=8080
[2005-07-06 12:57:56] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.22 destip=84.53.143.29 ipproto=TCP ipdatalen=28 srcport=1077 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:55] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.22 destip=84.53.143.29 ipproto=TCP ipdatalen=28 srcport=1077 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:55] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.22 destip=84.53.143.29 ipproto=TCP ipdatalen=28 srcport=1077 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:55] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.22 destip=84.53.143.24 ipproto=TCP ipdatalen=28 srcport=1076 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:55] <5>EFW: CONN: prio=2 rule=Rule_6 conn=open connipproto=TCP connrecvif=LAN connsrcip=192.168.1.16 connsrcport=4151 conndestif=core conndestip=192.168.1.1 conndestport=8080
[2005-07-06 12:57:54] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.22 destip=84.53.143.24 ipproto=TCP ipdatalen=28 srcport=1076 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:54] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.22 destip=84.53.143.24 ipproto=TCP ipdatalen=28 srcport=1076 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:54] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.22 destip=84.53.143.29 ipproto=TCP ipdatalen=28 srcport=1075 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:54] <5>EFW: CONN: prio=2 rule=Rule_6 conn=open connipproto=TCP connrecvif=LAN connsrcip=192.168.1.16 connsrcport=4150 conndestif=core conndestip=192.168.1.1 conndestport=8080
[2005-07-06 12:57:53] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.22 destip=84.53.143.29 ipproto=TCP ipdatalen=28 srcport=1075 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:53] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.22 destip=84.53.143.29 ipproto=TCP ipdatalen=28 srcport=1075 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:53] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.22 destip=84.53.143.24 ipproto=TCP ipdatalen=28 srcport=1074 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:52] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.22 destip=84.53.143.24 ipproto=TCP ipdatalen=28 srcport=1074 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:52] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.22 destip=84.53.143.24 ipproto=TCP ipdatalen=28 srcport=1074 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:52] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.22 destip=84.53.143.29 ipproto=TCP ipdatalen=28 srcport=1073 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:51] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.22 destip=84.53.143.29 ipproto=TCP ipdatalen=28 srcport=1073 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:51] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.22 destip=84.53.143.29 ipproto=TCP ipdatalen=28 srcport=1073 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:51] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.22 destip=84.53.143.24 ipproto=TCP ipdatalen=28 srcport=1072 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:50] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.22 destip=84.53.143.24 ipproto=TCP ipdatalen=28 srcport=1072 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:50] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.22 destip=84.53.143.24 ipproto=TCP ipdatalen=28 srcport=1072 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:50] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.22 destip=84.53.143.29 ipproto=TCP ipdatalen=28 srcport=1071 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:49] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.22 destip=84.53.143.29 ipproto=TCP ipdatalen=28 srcport=1071 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:49] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.22 destip=84.53.143.29 ipproto=TCP ipdatalen=28 srcport=1071 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:49] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.22 destip=84.53.143.24 ipproto=TCP ipdatalen=28 srcport=1070 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:48] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.22 destip=84.53.143.24 ipproto=TCP ipdatalen=28 srcport=1070 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:48] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.22 destip=84.53.143.24 ipproto=TCP ipdatalen=28 srcport=1070 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:41] <5>EFW: DROP: prio=2 rule=dropall-final action=drop recvif=LAN srcip=192.168.1.45 destip=192.168.1.1 ipproto=UDP ipdatalen=141 srcport=1032 destport=1900 udptotlen=141
[2005-07-06 12:57:41] <5>EFW: DROP: prio=2 rule=dropall-final action=drop recvif=LAN srcip=192.168.1.45 destip=192.168.1.1 ipproto=UDP ipdatalen=140 srcport=1032 destport=1900 udptotlen=140
[2005-07-06 12:57:41] <5>EFW: DROP: prio=2 rule=dropall-final action=drop recvif=LAN srcip=192.168.1.45 destip=192.168.1.1 ipproto=UDP ipdatalen=141 srcport=1032 destport=1900 udptotlen=141
[2005-07-06 12:57:41] <5>EFW: DROP: prio=2 rule=dropall-final action=drop recvif=LAN srcip=192.168.1.45 destip=192.168.1.1 ipproto=UDP ipdatalen=140 srcport=1032 destport=1900 udptotlen=140
[2005-07-06 12:57:37] <5>EFW: DROP: prio=2 rule=dropall-final action=drop recvif=WAN srcip=65.43.192.25 destip=80.237.23.233 ipproto=TCP ipdatalen=28 srcport=3673 destport=445 tcphdrlen=28 syn=1
[2005-07-06 12:57:34] <5>EFW: DROP: prio=2 rule=dropall-final action=drop recvif=WAN srcip=65.43.192.25 destip=80.237.23.233 ipproto=TCP ipdatalen=28 srcport=3673 destport=445 tcphdrlen=28 syn=1
[2005-07-06 12:57:31] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.41 destip=193.45.3.41 ipproto=TCP ipdatalen=28 srcport=1193 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:30] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.41 destip=193.45.3.41 ipproto=TCP ipdatalen=28 srcport=1193 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:30] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.41 destip=193.45.3.41 ipproto=TCP ipdatalen=28 srcport=1193 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:30] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.41 destip=217.107.212.198 ipproto=TCP ipdatalen=28 srcport=1192 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:30] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.41 destip=193.45.3.40 ipproto=TCP ipdatalen=28 srcport=1191 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:29] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.41 destip=217.107.212.198 ipproto=TCP ipdatalen=28 srcport=1192 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:29] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.41 destip=193.45.3.40 ipproto=TCP ipdatalen=28 srcport=1191 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:29] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.41 destip=217.107.212.198 ipproto=TCP ipdatalen=28 srcport=1192 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:29] <5>EFW: DROP: prio=2 rule=reject_standard action=reject recvif=LAN srcip=192.168.1.41 destip=193.45.3.40 ipproto=TCP ipdatalen=28 srcport=1191 destport=80 tcphdrlen=28 syn=1
[2005-07-06 12:57:19] <5>EFW: CONN: prio=2 rule=Rule_6 conn=open connipproto=TCP connrecvif=LAN connsrcip=192.168.1.16 connsrcport=4149 conndestif=core conndestip=192.168.1.1 conndestport=8080
[2005-07-06 12:57:16] <5>EFW: DROP: prio=2 rule=dropall-final action=drop recvif=LAN srcip=192.168.1.45 destip=192.168.1.1 ipproto=UDP ipdatalen=141 srcport=1032 destport=1900 udptotlen=141
[2005-07-06 12:57:16] <5>EFW: DROP: prio=2 rule=dropall-final action=drop recvif=LAN srcip=192.168.1.45 destip=192.168.1.1 ipproto=UDP ipdatalen=140 srcport=1032 destport=1900 udptotlen=140
[2005-07-06 12:57:16] <5>EFW: DROP: prio=2 rule=dropall-final action=drop recvif=LAN srcip=192.168.1.45 destip=192.168.1.1 ipproto=UDP ipdatalen=141 srcport=1032 destport=1900 udptotlen=141
[2005-07-06 12:57:16] <5>EFW: DROP: prio=2 rule=dropall-final action=drop recvif=LAN srcip=192.168.1.45 destip=192.168.1.1 ipproto=UDP ipdatalen=140 srcport=1032 destport=1900 udptotlen=140
[2005-07-06 12:57:13] <5>EFW: CONN: prio=2 rule=Rule_6 conn=open connipproto=TCP connrecvif=LAN connsrcip=192.168.1.16 connsrcport=4148 conndestif=core conndestip=192.168.1.1 conndestport=8080
Может, все дело в работе сигнатур IDS? Уж слишком уж много порождается событий и слишком уж много подропанных пакетов со стороны LAN... (Я поставил в правиле "Auth" опцию Intrusion Detection / Prevention в состояние Prevention).
Ничего не понимаю...