Цитата:
Nov 23 15:08:46 user warn syslog: dns query failed
Nov 23 15:10:57 daemon info pppd[233]: LCP terminated by peer
Nov 23 15:10:57 daemon info pppd[233]: Connect time 4679470.4 minutes.
Nov 23 15:10:57 daemon info pppd[233]: Sent 96469960 bytes, received 3393278164 bytes.
Nov 23 15:10:58 daemon warn pppd[233]: Couldn't increase MRU to 1500
Nov 23 15:11:01 daemon notice pppd[233]: Connection terminated....
Nov 23 15:11:07 daemon info pppd[233]: Sent PADT
Nov 23 15:11:07 daemon info pppd[233]: PPP session is 3395
Nov 23 15:11:07 daemon info pppd[233]: Using interface ppp0_8_35_1
Nov 23 15:11:07 daemon notice pppd[233]: Connect: ppp_0_8_35_1 <--> nas_0_8_35
Nov 23 15:11:08 daemon warn pppd[233]: Couldn't increase MRU to 1500
Nov 23 15:11:08 daemon warn pppd[233]: Couldn't increase MRU to 1500
Nov 23 15:11:08 daemon notice pppd[233]: PAP authentication succeeded
Nov 23 15:11:08 daemon notice pppd[233]: peer from calling number 00:90:1A:42:CA:B2 authorized
Nov 23 15:11:09 daemon notice pppd[233]: local IP address 92.101.114.83
Nov 23 15:11:09 daemon notice pppd[233]: remote IP address 91.122.208.1
Nov 23 15:11:09 daemon notice pppd[233]: primary DNS address 213.158.16.15
Nov 23 15:11:09 daemon notice pppd[233]: secondary DNS address 212.48.193.38
Nov 23 15:11:13 user debug syslog: route add default gw 91.122.208.1 2>/dev/null
Nov 23 15:11:13 user debug syslog: iptables -A FORWARD -o ppp_0_8_35_1 -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
Nov 23 15:11:13 user debug syslog: iptables -A FORWARD -i ppp_0_8_35_1 -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
Nov 23 15:11:14 user debug syslog: iptables -t nat -D POSTROUTING -o ppp_0_8_35_1 -s 192.168.1.0/255.255.255.0 -j MASQUERADE 2>/dev/null
Nov 23 15:11:14 user debug syslog: iptables -t nat -A POSTROUTING -o ppp_0_8_35_1 -s 192.168.1.0/255.255.255.0 -j MASQUERADE
Nov 23 15:12:00 user alert kernel: Intrusion -> IN=ppp_0_8_35_1 OUT= MAC= SRC=85.21.82.55 DST=92.101.114.83 LEN=60 TOS=0x00 PREC=0x20 TTL=53 ID=58283 DF PROTO=TCP SPT=48269 DPT=113 WINDOW=5840 RES=0x00 SYN URGP=0
Nov 23 15:12:03 user alert kernel: Intrusion -> IN=ppp_0_8_35_1 OUT= MAC= SRC=85.21.82.55 DST=92.101.114.83 LEN=60 TOS=0x00 PREC=0x20 TTL=53 ID=58284 DF PROTO=TCP SPT=48269 DPT=113 WINDOW=5840 RES=0x00 SYN URGP=0
Nov 23 15:12:06 user alert kernel: Intrusion -> IN=ppp_0_8_35_1 OUT= MAC= SRC=89.108.88.150 DST=92.101.114.83 LEN=64 TOS=0x00 PREC=0x20 TTL=56 ID=57958 DF PROTO=TCP SPT=63014 DPT=113 WINDOW=65535 RES=0x00 SYN URGP=0
Nov 23 15:12:06 user alert kernel: Intrusion -> IN=ppp_0_8_35_1 OUT= MAC= SRC=193.109.122.77 DST=92.101.114.83 LEN=64 TOS=0x00 PREC=0x20 TTL=57 ID=21209 DF PROTO=TCP SPT=44786 DPT=113 WINDOW=16384 RES=0x00 SYN URGP=0
Nov 23 15:12:06 user alert kernel: Intrusion -> IN=ppp_0_8_35_1 OUT= MAC= SRC=77.75.111.7 DST=92.101.114.83 LEN=60 TOS=0x00 PREC=0x20 TTL=56 ID=8069 DF PROTO=TCP SPT=51587 DPT=113 WINDOW=5840 RES=0x00 SYN URGP=0
Вот лог события на момент дефд-тайма.
Also, меня интересует вопрос - почему-то мигают значки
Status и
LAN, хотя они должны гореть постоянно, не так ли? Я в документации покопался, но о чем это сигнализирует - я не нашел. Думаю - ничего хорошего.