Davydov Denis писал(а):
Приведите лог устройства.
Мда, лог еще и выключен был. Включил, прочитал. Судя по количеству Intrusion возможно проблема в файерволе?
Jan 1 01:37:22 syslog emerg BCM96345 started: BusyBox v1.00 (2005.04.12-18:11+0000)
Jan 1 01:37:22 user crit kernel: eth0 Link UP.
Jan 1 01:37:22 user crit kernel: ADSL G.994 training
Jan 1 01:37:22 user crit kernel: ADSL G.992 started
Jan 1 01:37:22 user crit kernel: ADSL G.992 channel analysis
Jan 1 01:37:22 user crit kernel: ADSL link down
Jan 1 01:37:22 user crit kernel: ADSL G.994 training
Jan 1 01:37:22 user crit kernel: ADSL G.992 started
Jan 1 01:37:22 user crit kernel: ADSL G.992 channel analysis
Jan 1 01:37:22 user crit kernel: ADSL G.992 message exchange
Jan 1 01:37:22 user crit kernel: ADSL link up, interleaved, us=1021, ds=4093
Jan 1 01:37:22 user alert kernel: Intrusion -> IN=ppp_0_100_1 OUT= MAC= SRC=84.204.157.93 DST=84.204.167.83 LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=13842 DF PROTO=TCP SPT=1599 DPT=135 WINDOW=64800 RES=0x00 SYN URGP=0
Jan 1 01:37:22 user alert kernel: Intrusion -> IN=ppp_0_100_1 OUT= MAC= SRC=84.204.100.81 DST=84.204.167.83 LEN=48 TOS=0x00 PREC=0x00 TTL=124 ID=18464 DF PROTO=TCP SPT=4234 DPT=135 WINDOW=64240 RES=0x00 SYN URGP=0
Jan 1 01:37:22 user alert kernel: Intrusion -> IN=ppp_0_100_1 OUT= MAC= SRC=84.204.156.241 DST=84.204.167.83 LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=17198 DF PROTO=TCP SPT=4348 DPT=135 WINDOW=64240 RES=0x00 SYN URGP=0
Jan 1 01:37:22 user alert kernel: Intrusion -> IN=ppp_0_100_1 OUT= MAC= SRC=84.204.164.201 DST=84.204.167.83 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=32933 DF PROTO=TCP SPT=1873 DPT=135 WINDOW=64240 RES=0x00 SYN URGP=0
Jan 1 01:37:22 user alert kernel: Intrusion -> IN=ppp_0_100_1 OUT= MAC= SRC=84.204.157.93 DST=84.204.167.83 LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=31451 DF PROTO=TCP SPT=1108 DPT=135 WINDOW=64800 RES=0x00 SYN URGP=0
Jan 1 01:37:22 user alert kernel: Intrusion -> IN=ppp_0_100_1 OUT= MAC= SRC=84.204.166.180 DST=84.204.167.83 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=52203 DF PROTO=TCP SPT=1372 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
Jan 1 01:37:22 user alert kernel: Intrusion -> IN=ppp_0_100_1 OUT= MAC= SRC=84.204.166.180 DST=84.204.167.83 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=52311 DF PROTO=TCP SPT=1372 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
Jan 1 01:37:22 user alert kernel: Intrusion -> IN=ppp_0_100_1 OUT= MAC= SRC=84.204.100.81 DST=84.204.167.83 LEN=48 TOS=0x00 PREC=0x00 TTL=124 ID=20980 DF PROTO=TCP SPT=4486 DPT=135 WINDOW=64240 RES=0x00 SYN URGP=0
Jan 1 01:37:22 user alert kernel: Intrusion -> IN=ppp_0_100_1 OUT= MAC= SRC=84.204.101.52 DST=84.204.167.83 LEN=48 TOS=0x00 PREC=0x00 TTL=125 ID=28885 DF PROTO=TCP SPT=3032 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
Jan 1 01:37:22 user alert kernel: Intrusion -> IN=ppp_0_100_1 OUT= MAC= SRC=84.204.164.37 DST=84.204.167.83 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=21901 DF PROTO=TCP SPT=1040 DPT=135 WINDOW=16384 RES=0x00 SYN URGP=0
Jan 1 01:37:22 user alert kernel: Intrusion -> IN=ppp_0_100_1 OUT= MAC= SRC=84.204.166.87 DST=84.204.167.83 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=41288 DF PROTO=TCP SPT=3036 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
Jan 1 01:37:22 user alert kernel: Intrusion -> IN=ppp_0_100_1 OUT= MAC= SRC=84.204.101.143 DST=84.204.167.83 LEN=48 TOS=0x00 PREC=0x00 TTL=125 ID=16163 DF PROTO=TCP SPT=3104 DPT=135 WINDOW=64800 RES=0x00 SYN URGP=0
Jan 1 01:37:22 user alert kernel: Intrusion -> IN=ppp_0_100_1 OUT= MAC= SRC=84.113.1.65 DST=84.204.167.83 LEN=48 TOS=0x00 PREC=0x00 TTL=109 ID=36438 DF PROTO=TCP SPT=2446 DPT=2967 WINDOW=64240 RES=0x00 SYN URGP=0
Jan 1 01:37:22 user alert kernel: Intrusion -> IN=ppp_0_100_1 OUT= MAC= SRC=84.204.164.37 DST=84.204.167.83 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=40661 DF PROTO=TCP SPT=3642 DPT=135 WINDOW=16384 RES=0x00 SYN URGP=0
Jan 1 01:37:22 user alert kernel: Intrusion -> IN=ppp_0_100_1 OUT= MAC= SRC=84.204.157.39 DST=84.204.167.83 LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=39694 DF PROTO=TCP SPT=2519 DPT=135 WINDOW=64240 RES=0x00 SYN URGP=0
Jan 1 01:37:22 user alert kernel: Intrusion -> IN=ppp_0_100_1 OUT= MAC= SRC=84.204.157.39 DST=84.204.167.83 LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=27625 DF PROTO=TCP SPT=1830 DPT=135 WINDOW=64240 RES=0x00 SYN URGP=0
Jan 1 01:37:22 user alert kernel: Intrusion -> IN=ppp_0_100_1 OUT= MAC= SRC=84.204.157.36 DST=84.204.167.83 LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=4352 DF PROTO=TCP SPT=4111 DPT=445 WINDOW=64240 RES=0x00 SYN URGP=0