dns query failed - уже около 24 часов не появлялось.
Неужели навсегда пропало? Будет скучно жить - тьфу тьфу тьфу!
вот лог -
System Log
Date/Time Facility Severity Message
Jul 27 15:29:37 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=217.117.112.158 DST=91.124.57.87 LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=35627 DF PROTO=TCP SPT=2486 DPT=46019 WINDOW=64240 RES=0x00 SYN URGP=0
Jul 27 15:40:27 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=91.124.200.103 DST=91.124.57.87 LEN=48 TOS=0x00 PREC=0x00 TTL=126 ID=5511 DF PROTO=TCP SPT=9539 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
Jul 27 15:49:32 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=91.124.233.224 DST=91.124.57.87 LEN=48 TOS=0x00 PREC=0x00 TTL=126 ID=50432 DF PROTO=TCP SPT=4808 DPT=135 WINDOW=64800 RES=0x00 SYN URGP=0
Jul 27 15:58:10 daemon crit pppd[309]: Clear IP addresses. Connection DOWN.
Jul 27 15:58:10 daemon crit pppd[309]: Clear IP addresses. PPP connection DOWN.
Jul 27 15:58:16 daemon notice pppd[309]: PPP: Start to connect ...
Jul 27 15:58:16 daemon crit pppd[309]: PPP server detected.
Jul 27 15:58:16 daemon crit pppd[309]: PPP session established.
Jul 27 15:58:16 daemon crit pppd[309]: PPP LCP UP.
Jul 27 15:58:18 daemon crit pppd[309]: Received valid IP address from server. Connection UP.
Jul 27 15:58:19 user debug syslog: route add default dev ppp_1_32_1 2>/dev/null
Jul 27 15:58:20 user debug syslog: iptables -A FORWARD -o ppp_1_32_1 -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
Jul 27 15:58:20 user debug syslog: iptables -A FORWARD -i ppp_1_32_1 -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
Jul 27 15:58:20 user debug syslog: iptables -t nat -D POSTROUTING -o ppp_1_32_1 -s 192.168.1.0/255.255.255.0 -j MASQUERADE 2>/dev/null
Jul 27 15:58:20 user debug syslog: iptables -t nat -A POSTROUTING -o ppp_1_32_1 -s 192.168.1.0/255.255.255.0 -j MASQUERADE
Jul 27 15:58:21 user debug syslog: iptables -D INPUT -i ppp_1_32_1 -j DROP
Jul 27 15:58:21 user debug syslog: iptables -A INPUT -i ppp_1_32_1 -j DROP
Jul 27 15:58:59 syslog info -- MARK --
Jul 27 15:59:04 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=91.124.12.178 DST=91.124.0.156 LEN=60 TOS=0x00 PREC=0x00 TTL=63 ID=24942 DF PROTO=TCP SPT=2191 DPT=23 WINDOW=5808 RES=0x00 SYN URGP=0
Jul 27 15:59:07 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=91.124.110.100 DST=91.124.0.156 LEN=48 TOS=0x00 PREC=0x00 TTL=126 ID=19307 DF PROTO=TCP SPT=4406 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
Jul 27 15:59:07 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=91.124.12.178 DST=91.124.0.156 LEN=60 TOS=0x00 PREC=0x00 TTL=63 ID=24943 DF PROTO=TCP SPT=2191 DPT=23 WINDOW=5808 RES=0x00 SYN URGP=0
Jul 27 15:59:10 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=91.124.110.100 DST=91.124.0.156 LEN=48 TOS=0x00 PREC=0x00 TTL=126 ID=19498 DF PROTO=TCP SPT=4406 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
Jul 27 15:59:10 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=91.124.248.15 DST=91.124.0.156 LEN=52 TOS=0x00 PREC=0x00 TTL=62 ID=34599 DF PROTO=TCP SPT=32278 DPT=135 WINDOW=60352 RES=0x00 SYN URGP=0
Jul 27 16:09:13 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=91.124.250.185 DST=91.124.0.156 LEN=64 TOS=0x00 PREC=0x00 TTL=46 ID=35902 DF PROTO=TCP SPT=4723 DPT=135 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 16:19:07 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=91.124.102.247 DST=91.124.0.156 LEN=48 TOS=0x00 PREC=0x00 TTL=126 ID=9214 DF PROTO=TCP SPT=4333 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
Jul 27 16:29:15 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=91.124.249.119 DST=91.124.0.156 LEN=48 TOS=0x00 PREC=0x00 TTL=126 ID=45038 DF PROTO=TCP SPT=1960 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
Jul 27 16:39:15 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=91.124.168.142 DST=91.124.0.156 LEN=48 TOS=0x00 PREC=0x00 TTL=125 ID=2059 DF PROTO=TCP SPT=1712 DPT=445 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 16:49:08 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=91.124.105.120 DST=91.124.0.156 LEN=48 TOS=0x00 PREC=0x00 TTL=126 ID=44057 DF PROTO=TCP SPT=3357 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
Jul 27 16:59:00 syslog info -- MARK --
Jul 27 16:59:22 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=91.124.107.239 DST=91.124.0.156 LEN=48 TOS=0x00 PREC=0x00 TTL=126 ID=2112 DF PROTO=TCP SPT=3234 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
Jul 27 17:09:48 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=91.124.200.103 DST=91.124.0.156 LEN=48 TOS=0x00 PREC=0x00 TTL=126 ID=37529 DF PROTO=TCP SPT=24457 DPT=2967 WINDOW=64800 RES=0x00 SYN URGP=0
Jul 27 17:19:22 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=91.124.138.174 DST=91.124.0.156 LEN=52 TOS=0x00 PREC=0x00 TTL=62 ID=19945 DF PROTO=TCP SPT=38719 DPT=445 WINDOW=60352 RES=0x00 SYN URGP=0
Jul 27 17:29:12 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=91.124.194.126 DST=91.124.0.156 LEN=48 TOS=0x00 PREC=0x00 TTL=126 ID=6450 DF PROTO=TCP SPT=25026 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
Jul 27 17:39:43 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=91.124.235.129 DST=91.124.0.156 LEN=52 TOS=0x00 PREC=0x00 TTL=62 ID=58029 DF PROTO=TCP SPT=1185 DPT=135 WINDOW=64240 RES=0x00 SYN URGP=0
Jul 27 17:49:23 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=91.124.194.126 DST=91.124.0.156 LEN=48 TOS=0x00 PREC=0x00 TTL=126 ID=26680 DF PROTO=TCP SPT=7706 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
Jul 27 17:58:59 syslog info -- MARK --
Jul 27 17:59:18 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=91.124.252.178 DST=91.124.0.156 LEN=48 TOS=0x00 PREC=0x00 TTL=126 ID=56397 DF PROTO=TCP SPT=2938 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
Jul 27 18:09:06 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=91.124.240.162 DST=91.124.0.156 LEN=48 TOS=0x00 PREC=0x00 TTL=126 ID=37654 DF PROTO=TCP SPT=3053 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
Jul 27 18:19:55 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=91.124.246.245 DST=91.124.0.156 LEN=52 TOS=0x00 PREC=0x00 TTL=62 ID=8724 DF PROTO=TCP SPT=23314 DPT=135 WINDOW=60352 RES=0x00 SYN URGP=0
Jul 27 18:30:11 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=91.124.148.125 DST=91.124.0.156 LEN=48 TOS=0x00 PREC=0x00 TTL=126 ID=62127 DF PROTO=TCP SPT=4421 DPT=2967 WINDOW=64800 RES=0x00 SYN URGP=0
Jul 27 18:40:21 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=91.124.102.247 DST=91.124.0.156 LEN=48 TOS=0x00 PREC=0x00 TTL=126 ID=14916 DF PROTO=TCP SPT=3152 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
Jul 27 18:45:37 user crit kernel: eth0 Link DOWN.
Jul 27 18:45:38 user info kernel: br0: port 1(eth0) entering disabled state
Jul 27 18:45:40 user crit kernel: eth0 Link UP.
Jul 27 18:45:40 user info kernel: br0: port 1(eth0) entering learning state
Jul 27 18:45:40 user info kernel: br0: topology change detected, propagating
Jul 27 18:45:40 user info kernel: br0: port 1(eth0) entering forwarding state
Jul 27 18:49:04 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=91.124.201.50 DST=91.124.0.156 LEN=48 TOS=0x00 PREC=0x00 TTL=126 ID=40648 DF PROTO=TCP SPT=4866 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
Jul 27 18:59:00 syslog info -- MARK --
Jul 27 19:00:26 user alert kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=213.232.194.213 DST=91.124.0.156 LEN=48 TOS=0x00 PREC=0x00 TTL=119 ID=35275 DF PROTO=TCP SPT=1434 DPT=37261 WINDOW=65535 RES=0x00 SYN URGP=0
я так понимаю объём лога ограничен? Потому как не передёргивал машинку уже 24 часа.
это на последней прошивке J.
Board ID: D-4P
Software Version: RU_DSL-2540U_3-06-04-3J00.A2pB023g2.d19b
Bootloader (CFE) Version: 1.0.37-6.5
This information reflects the current status of your DSL connection.
И вот что поменял в настройках. dns прописал вручную, шлюз как видно поставил ppp_1_32_1
keep alive активирован.
Enable IGMP Snooping активирован
Line Rate - Upstream (Kbps): 346
Line Rate - Downstream (Kbps): 623
LAN IP Address: 192.168.1.1
Default Gateway: ppp_1_32_1
Primary DNS Server: 195.5.46.12
Secondary DNS Server: 195.5.46.11
Date/Time: Sun Jul 27 19:12:28 2008
а вот свойства adsl
Mode: G.DMT
Type: Interleave
Line Coding: Trellis On
Status: No Defect
Link Power State: L0
Downstream Upstream
SNR Margin (dB): 31.8 31.0
Attenuation (dB): 42.0 24.0
Output Power (dBm): 11.9 10.4
Attainable Rate (Kbps): 8860 1380
Rate (Kbps): 623 346
K (number of bytes in DMT frame): 19 11
R (number of check bytes in RS code word): 16 12
S (RS code word size in DMT frame): 8 4
D (interleaver depth): 8 4
Delay (msec): 16 4
Super Frames: 5769962 5769960
Super Frame Errors: 1 0
RS Words: 49044680 98089320
RS Correctable Errors: 281 0
RS Uncorrectable Errors: 6 N/A
HEC Errors: 1 0
OCD Errors: 0 0
LCD Errors: 0 0
Total Cells: 144033375 0
Data Cells: 2037245 0
Bit Errors: 0 0
Total ES: 1 0
Total SES: 0 0
Total UAS: 10 0
будем надеяться
хотя закрадывается ещё одно нехорошее подозрение, всё это происходит с вечера субботы по сей момент - вечер воскресенья.
линии УТК наверное не очень загружены, возможно в этом всё дело?
Посмотрим что будет завтра в понедельник
