Demis73 писал(а):
mvj писал(а):
Приведите системный лог модема в момент разрыва соединения.
[/quote]
вот
индикатор работал стабильно
Mar 13 16:26:41 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=61.210.188.138 DST=94.28.165.61 LEN=64 TOS=0x08 PREC=0x40 TTL=252 ID=6798 DF PROTO=TCP SPT=1372 DPT=445 WINDOW=53760 RES=0x00 SYN URGP=0
Mar 13 16:37:19 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=87.7.36.112 DST=94.28.165.61 LEN=48 TOS=0x08 PREC=0x40 TTL=252 ID=35229 DF PROTO=TCP SPT=4270 DPT=445 WINDOW=65535 RES=0x00 SYN URGP=0
Mar 13 16:46:30 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=91.188.44.127 DST=94.28.165.61 LEN=48 TOS=0x08 PREC=0x00 TTL=114 ID=26236 DF PROTO=TCP SPT=2448 DPT=445 WINDOW=65535 RES=0x00 SYN URGP=0
Mar 13 16:57:20 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=188.187.248.66 DST=94.28.165.61 LEN=40 TOS=0x08 PREC=0x00 TTL=244 ID=256 PROTO=TCP SPT=6000 DPT=135 WINDOW=16384 RES=0x00 SYN URGP=0
Mar 13 17:01:53 daemon crit pppd[709]: Connection terminated....
Mar 13 17:01:59 daemon crit pppd[709]: Connect: ppp_0_0_35_1 <--> nas_0_0_35
Mar 13 17:02:46 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=88.84.218.243 DST=95.139.139.164 LEN=48 TOS=0x08 PREC=0x00 TTL=252 ID=58197 DF PROTO=TCP SPT=1324 DPT=13223 WINDOW=64380 RES=0x00 SYN URGP=0
Mar 13 17:02:49 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=88.84.218.243 DST=95.139.139.164 LEN=48 TOS=0x08 PREC=0x00 TTL=119 ID=58345 DF PROTO=TCP SPT=1324 DPT=13223 WINDOW=64380 RES=0x00 SYN URGP=0
Mar 13 17:02:55 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=88.84.218.243 DST=95.139.139.164 LEN=48 TOS=0x08 PREC=0x00 TTL=119 ID=58661 DF PROTO=TCP SPT=1324 DPT=13223 WINDOW=64380 RES=0x00 SYN URGP=0
Mar 13 17:02:56 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=88.84.218.243 DST=95.139.139.164 LEN=48 TOS=0x08 PREC=0x00 TTL=119 ID=58755 DF PROTO=TCP SPT=1413 DPT=13223 WINDOW=64380 RES=0x00 SYN URGP=0
Mar 13 17:02:59 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=91.202.86.91 DST=95.139.139.164 LEN=52 TOS=0x08 PREC=0x00 TTL=252 ID=5367 DF PROTO=TCP SPT=57914 DPT=12047 WINDOW=8192 RES=0x00 SYN URGP=0
Mar 13 17:12:47 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=88.84.218.243 DST=95.139.139.164 LEN=48 TOS=0x08 PREC=0x00 TTL=119 ID=27350 DF PROTO=TCP SPT=2493 DPT=13223 WINDOW=64380 RES=0x00 SYN URGP=0
Mar 13 17:22:48 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=88.84.218.243 DST=95.139.139.164 LEN=48 TOS=0x08 PREC=0x00 TTL=119 ID=64029 DF PROTO=TCP SPT=3652 DPT=13223 WINDOW=64380 RES=0x00 SYN URGP=0
Mar 13 17:32:48 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=88.84.218.243 DST=95.139.139.164 LEN=48 TOS=0x08 PREC=0x00 TTL=119 ID=64223 DF PROTO=TCP SPT=4888 DPT=13223 WINDOW=64380 RES=0x00 SYN URGP=0
Mar 13 17:42:52 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=46.63.130.192 DST=95.139.139.164 LEN=48 TOS=0x08 PREC=0x00 TTL=114 ID=14509 DF PROTO=TCP SPT=3324 DPT=37540 WINDOW=65535 RES=0x00 SYN URGP=0
Mar 13 17:50:35 daemon crit pppd[709]: Connection terminated....
Mar 13 17:50:42 daemon crit pppd[709]: Connect: ppp_0_0_35_1 <--> nas_0_0_35
Mar 13 17:52:37 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=178.35.255.241 DST=94.28.150.29 LEN=48 TOS=0x08 PREC=0x00 TTL=115 ID=58967 PROTO=TCP SPT=4611 DPT=51177 WINDOW=65535 RES=0x00 SYN URGP=0
Mar 13 17:52:40 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=178.35.255.241 DST=94.28.150.29 LEN=48 TOS=0x08 PREC=0x00 TTL=115 ID=59296 PROTO=TCP SPT=4611 DPT=51177 WINDOW=65535 RES=0x00 SYN URGP=0
Mar 13 17:52:46 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=178.35.255.241 DST=94.28.150.29 LEN=48 TOS=0x08 PREC=0x00 TTL=115 ID=59499 PROTO=TCP SPT=4611 DPT=51177 WINDOW=65535 RES=0x00 SYN URGP=0
Mar 13 17:52:54 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=188.173.70.200 DST=94.28.150.29 LEN=48 TOS=0x08 PREC=0x40 TTL=252 ID=45166 DF PROTO=TCP SPT=3552 DPT=445 WINDOW=65535 RES=0x00 SYN URGP=0
Mar 13 17:52:57 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=188.173.70.200 DST=94.28.150.29 LEN=48 TOS=0x08 PREC=0x40 TTL=252 ID=45885 DF PROTO=TCP SPT=3552 DPT=445 WINDOW=65535 RES=0x00 SYN URGP=0
Mar 13 17:58:18 daemon crit pppd[709]: Connection terminated....
Mar 13 17:58:24 daemon crit pppd[709]: Connect: ppp_0_0_35_1 <--> nas_0_0_35
Mar 13 18:01:02 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=195.208.239.11 DST=95.139.132.78 LEN=48 TOS=0x08 PREC=0x00 TTL=115 ID=37866 DF PROTO=TCP SPT=26871 DPT=62933 WINDOW=65535 RES=0x00 SYN URGP=0
Mar 13 18:01:05 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=195.208.239.11 DST=95.139.132.78 LEN=48 TOS=0x08 PREC=0x00 TTL=115 ID=38071 DF PROTO=TCP SPT=26871 DPT=62933 WINDOW=65535 RES=0x00 SYN URGP=0
Mar 13 18:01:11 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=195.208.239.11 DST=95.139.132.78 LEN=48 TOS=0x08 PREC=0x00 TTL=115 ID=38595 DF PROTO=TCP SPT=26871 DPT=62933 WINDOW=65535 RES=0x00 SYN URGP=0
Mar 13 18:05:30 daemon crit pppd[709]: Connection terminated....
Mar 13 18:05:36 daemon crit pppd[709]: Connect: ppp_0_0_35_1 <--> nas_0_0_35
Mar 13 18:06:57 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=94.28.19.162 DST=94.28.177.125 LEN=48 TOS=0x08 PREC=0x00 TTL=252 ID=22665 DF PROTO=TCP SPT=22092 DPT=445 WINDOW=16384 RES=0x00 SYN URGP=0
Mar 13 18:08:07 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=217.66.22.11 DST=94.28.177.125 LEN=48 TOS=0x08 PREC=0x00 TTL=111 ID=65131 PROTO=TCP SPT=2095 DPT=42550 WINDOW=64380 RES=0x00 SYN URGP=0
Mar 13 18:08:10 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=217.66.22.11 DST=94.28.177.125 LEN=48 TOS=0x08 PREC=0x00 TTL=111 ID=65277 PROTO=TCP SPT=2095 DPT=42550 WINDOW=64380 RES=0x00 SYN URGP=0
Mar 13 18:08:15 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=217.66.22.11 DST=94.28.177.125 LEN=48 TOS=0x08 PREC=0x00 TTL=111 ID=65478 PROTO=TCP SPT=2095 DPT=42550 WINDOW=64380 RES=0x00 SYN URGP=0
Mar 13 18:08:41 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=213.138.93.146 DST=94.28.177.125 LEN=48 TOS=0x08 PREC=0x00 TTL=114 ID=53646 DF PROTO=TCP SPT=3865 DPT=42550 WINDOW=65535 RES=0x00 SYN URGP=0
Mar 13 18:13:13 daemon crit pppd[709]: Connection terminated....
Mar 13 18:13:19 daemon err pppd[709]: Access concentrator used a session value of 0 -- the AC is violating RFC 2516
Mar 13 18:13:19 daemon err pppd[709]: Couldn't get channel number: Transport endpoint is not connected
Mar 13 18:13:25 daemon crit pppd[709]: Connect: ppp_0_0_35_1 <--> nas_0_0_35
Mar 13 18:18:04 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.255.55.196 DST=95.139.137.104 LEN=40 TOS=0x08 PREC=0x00 TTL=252 ID=256 PROTO=TCP SPT=6000 DPT=135 WINDOW=16384 RES=0x00 SYN URGP=0
Mar 13 18:18:04 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.255.55.196 DST=95.139.137.104 LEN=40 TOS=0x08 PREC=0x00 TTL=252 ID=256 PROTO=TCP SPT=6000 DPT=1433 WINDOW=16384 RES=0x00 SYN URGP=0
Mar 13 18:21:31 daemon crit pppd[709]: Connection terminated....
Mar 13 18:21:37 daemon crit pppd[709]: Connect: ppp_0_0_35_1 <--> nas_0_0_35
Mar 13 18:22:08 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=91.124.134.252 DST=95.139.172.25 LEN=48 TOS=0x08 PREC=0x00 TTL=252 ID=34310 DF PROTO=TCP SPT=58371 DPT=20446 WINDOW=65535 RES=0x00 SYN URGP=0
Mar 13 18:22:14 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=91.124.134.252 DST=95.139.172.25 LEN=48 TOS=0x08 PREC=0x00 TTL=252 ID=34609 DF PROTO=TCP SPT=58371 DPT=20446 WINDOW=65535 RES=0x00 SYN URGP=0
Mar 13 18:28:13 daemon crit pppd[709]: Connection terminated....
Mar 13 18:28:19 daemon err pppd[709]: Access concentrator used a session value of 0 -- the AC is violating RFC 2516
Mar 13 18:28:19 daemon err pppd[709]: Couldn't get channel number: Transport endpoint is not connected
Mar 13 18:28:25 daemon err pppd[709]: Access concentrator used a session value of 0 -- the AC is violating RFC 2516
Mar 13 18:28:25 daemon err pppd[709]: Couldn't get channel number: Transport endpoint is not connected
Mar 13 18:28:32 daemon err pppd[709]: Access concentrator used a session value of 0 -- the AC is violating RFC 2516
Mar 13 18:28:32 daemon err pppd[709]: Couldn't get channel number: Transport endpoint is not connected
Mar 13 18:28:38 daemon err pppd[709]: Access concentrator used a session value of 0 -- the AC is violating RFC 2516
Mar 13 18:28:38 daemon err pppd[709]: Couldn't get channel number: Transport endpoint is not connected
Mar 13 18:28:44 daemon err pppd[709]: Access concentrator used a session value of 0 -- the AC is violating RFC 2516
Mar 13 18:28:44 daemon err pppd[709]: Couldn't get channel number: Transport endpoint is not connected
Mar 13 18:28:50 daemon crit pppd[709]: Connect: ppp_0_0_35_1 <--> nas_0_0_35
Mar 13 18:29:31 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=46.185.23.23 DST=94.28.198.77 LEN=48 TOS=0x08 PREC=0x00 TTL=252 ID=19585 DF PROTO=TCP SPT=62104 DPT=63979 WINDOW=8192 RES=0x00 SYN URGP=0
Mar 13 18:29:32 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=77.39.5.74 DST=94.28.198.77 LEN=52 TOS=0x08 PREC=0x00 TTL=252 ID=14831 DF PROTO=TCP SPT=1883 DPT=63979 WINDOW=64240 RES=0x00 SYN URGP=0
Mar 13 18:29:35 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=76.10.162.8 DST=94.28.198.77 LEN=52 TOS=0x08 PREC=0x00 TTL=111 ID=11864 DF PROTO=TCP SPT=61808 DPT=63979 WINDOW=8192 RES=0x00 SYN URGP=0
Mar 13 18:29:38 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=46.185.23.23 DST=94.28.198.77 LEN=48 TOS=0x08 PREC=0x00 TTL=252 ID=19990 DF PROTO=TCP SPT=62104 DPT=63979 WINDOW=8192 RES=0x00 SYN URGP=0
Mar 13 18:29:38 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=76.10.162.8 DST=94.28.198.77 LEN=52 TOS=0x08 PREC=0x00 TTL=111 ID=11936 DF PROTO=TCP SPT=61808 DPT=63979 WINDOW=8192 RES=0x00 SYN URGP=0
Mar 13 18:36:26 daemon crit pppd[709]: Connection terminated....
Mar 13 18:36:32 daemon crit pppd[709]: Connect: ppp_0_0_35_1 <--> nas_0_0_35
Mar 13 18:37:35 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=46.5.162.18 DST=95.139.243.188 LEN=48 TOS=0x08 PREC=0x40 TTL=115 ID=18778 DF PROTO=TCP SPT=58238 DPT=51883 WINDOW=8192 RES=0x00 SYN URGP=0
Mar 13 18:37:36 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=212.45.29.253 DST=95.139.243.188 LEN=48 TOS=0x08 PREC=0x00 TTL=116 ID=8356 DF PROTO=TCP SPT=2500 DPT=51883 WINDOW=65535 RES=0x00 SYN URGP=0
Mar 13 18:37:36 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=94.41.120.75 DST=95.139.243.188 LEN=48 TOS=0x08 PREC=0x00 TTL=114 ID=41518 DF PROTO=TCP SPT=2571 DPT=51883 WINDOW=65535 RES=0x00 SYN URGP=0
Mar 13 18:37:36 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=109.173.22.52 DST=95.139.243.188 LEN=52 TOS=0x08 PREC=0x00 TTL=252 ID=2244 DF PROTO=TCP SPT=59260 DPT=51883 WINDOW=8192 RES=0x00 SYN URGP=0
Mar 13 18:37:38 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=71.56.129.124 DST=95.139.243.188 LEN=48 TOS=0x08 PREC=0x40 TTL=114 ID=24360 DF PROTO=TCP SPT=52930 DPT=51883 WINDOW=8192 RES=0x00 SYN URGP=0
Mar 13 18:43:38 daemon crit pppd[709]: Connection terminated....
Mar 13 18:43:45 daemon crit pppd[709]: Connect: ppp_0_0_35_1 <--> nas_0_0_35
Mar 13 18:45:13 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=217.8.225.55 DST=94.28.136.56 LEN=48 TOS=0x08 PREC=0x00 TTL=252 ID=20013 DF PROTO=TCP SPT=32355 DPT=6881 WINDOW=64240 RES=0x00 SYN URGP=0
Mar 13 18:45:16 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=217.8.225.55 DST=94.28.136.56 LEN=48 TOS=0x08 PREC=0x00 TTL=252 ID=20057 DF PROTO=TCP SPT=32355 DPT=6881 WINDOW=64240 RES=0x00 SYN URGP=0
Mar 13 18:45:19 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=94.73.44.237 DST=94.28.136.56 LEN=48 TOS=0x08 PREC=0x40 TTL=114 ID=8068 DF PROTO=TCP SPT=1813 DPT=445 WINDOW=65535 RES=0x00 SYN URGP=0
Mar 13 18:45:22 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=94.73.44.237 DST=94.28.136.56 LEN=48 TOS=0x08 PREC=0x40 TTL=114 ID=8302 DF PROTO=TCP SPT=1813 DPT=445 WINDOW=65535 RES=0x00 SYN URGP=0
Mar 13 18:47:02 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=81.177.144.9 DST=94.28.136.56 LEN=40 TOS=0x08 PREC=0x00 TTL=252 ID=256 PROTO=TCP SPT=6000 DPT=1433 WINDOW=16384 RES=0x00 SYN URGP=0
Mar 13 18:51:21 daemon crit pppd[709]: Connection terminated....
Mar 13 18:51:27 daemon err pppd[709]: Access concentrator used a session value of 0 -- the AC is violating RFC 2516
Mar 13 18:51:27 daemon err pppd[709]: Couldn't get channel number: Transport endpoint is not connected
Mar 13 18:51:33 daemon crit pppd[709]: Connect: ppp_0_0_35_1 <--> nas_0_0_35
Mar 13 18:53:01 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=89.189.169.76 DST=95.139.179.106 LEN=48 TOS=0x08 PREC=0x00 TTL=252 ID=20636 DF PROTO=TCP SPT=2440 DPT=56950 WINDOW=65535 RES=0x00 SYN URGP=0
Mar 13 18:53:04 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=89.189.169.76 DST=95.139.179.106 LEN=48 TOS=0x08 PREC=0x00 TTL=252 ID=21294 DF PROTO=TCP SPT=2440 DPT=56950 WINDOW=65535 RES=0x00 SYN URGP=0
Mar 13 18:53:10 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=89.189.169.76 DST=95.139.179.106 LEN=48 TOS=0x08 PREC=0x00 TTL=252 ID=23132 DF PROTO=TCP SPT=2440 DPT=56950 WINDOW=65535 RES=0x00 SYN URGP=0
Mar 13 18:56:05 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=46.185.40.70 DST=95.139.179.106 LEN=52 TOS=0x08 PREC=0x00 TTL=252 ID=28956 DF PROTO=TCP SPT=50188 DPT=54545 WINDOW=8192 RES=0x00 SYN URGP=0
Mar 13 18:56:08 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=46.185.40.70 DST=95.139.179.106 LEN=52 TOS=0x08 PREC=0x00 TTL=252 ID=30276 DF PROTO=TCP SPT=50188 DPT=54545 WINDOW=8192 RES=0x00 SYN URGP=0
Mar 13 18:59:09 daemon crit pppd[709]: Connection terminated....
Mar 13 18:59:15 daemon crit pppd[709]: Connect: ppp_0_0_35_1 <--> nas_0_0_35
Mar 13 19:00:19 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=95.58.145.9 DST=94.28.204.97 LEN=48 TOS=0x08 PREC=0x00 TTL=111 ID=39448 DF PROTO=TCP SPT=4356 DPT=35691 WINDOW=65535 RES=0x00 SYN URGP=0
Mar 13 19:00:20 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=95.139.239.73 DST=94.28.204.97 LEN=52 TOS=0x08 PREC=0x00 TTL=252 ID=17995 DF PROTO=TCP SPT=56089 DPT=11176 WINDOW=8192 RES=0x00 SYN URGP=0
Mar 13 19:00:20 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=90.150.129.241 DST=94.28.204.97 LEN=48 TOS=0x08 PREC=0x00 TTL=252 ID=27789 DF PROTO=TCP SPT=4304 DPT=11176 WINDOW=65535 RES=0x00 SYN URGP=0
Mar 13 19:00:23 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=95.139.239.73 DST=94.28.204.97 LEN=52 TOS=0x08 PREC=0x00 TTL=252 ID=18078 DF PROTO=TCP SPT=56089 DPT=11176 WINDOW=8192 RES=0x00 SYN URGP=0
Mar 13 19:00:25 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=95.58.145.9 DST=94.28.204.97 LEN=48 TOS=0x08 PREC=0x00 TTL=111 ID=39826 DF PROTO=TCP SPT=4356 DPT=35691 WINDOW=65535 RES=0x00 SYN URGP=0