Не понятные запросы к роутеру и как с ними бороться
Добавлено: 14 дек 2020, 21:46
Доброго времени суток. Подскажите что это за сканирование портов и как с ним бороться? Что означает len ХХ?
Под данные правила фаервола блокировки сканирования портов не попадают:20:30:17 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto TCP (SYN), 46.188.40.184:58796->193.37.192.249:52169, len 52
20:30:17 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto TCP (SYN), 85.115.189.100:57424->193.37.192.249:52169, len 60
20:30:17 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto TCP (SYN), 87.255.8.150:56034->193.37.192.249:52169, len 52
20:30:17 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto TCP (SYN), 37.21.198.176:21131->193.37.192.249:52169, len 48
20:30:17 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto TCP (SYN), 93.100.167.140:61789->193.37.192.249:52169, len 52
20:30:17 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto TCP (SYN), 92.63.196.36:44240->193.37.192.249:65065, len 40
20:30:17 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto TCP (SYN), 188.243.3.85:63466->193.37.192.249:52169, len 52
20:30:17 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto UDP, 93.100.167.140:34675->193.37.192.249:52169, len 48
20:30:17 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto UDP, 31.40.126.55:1412->193.37.192.249:52169, len 48
20:30:17 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto UDP, 5.141.81.19:13638->193.37.192.249:1, len 132
20:30:18 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto UDP, 141.226.165.95:62297->193.37.192.249:52169, len 48
20:30:18 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto TCP (SYN), 141.226.165.95:51183->193.37.192.249:52169, len 52
20:30:18 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto UDP, 176.57.76.129:49959->193.37.192.249:52169, len 48
20:30:18 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto UDP, 213.111.180.198:16119->193.37.192.249:52169, len 48
20:30:18 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto TCP (SYN), 93.81.223.166:56546->193.37.192.249:52169, len 52
20:30:19 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto UDP, 50.67.4.100:15985->193.37.192.249:52169, len 126
20:30:19 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto UDP, 79.146.118.11:24575->193.37.192.249:52169, len 126
20:30:19 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto TCP (SYN), 93.73.28.103:60093->193.37.192.249:52169, len 48
20:30:19 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto TCP (SYN), 46.188.40.184:58796->193.37.192.249:52169, len 52
20:30:19 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto TCP (SYN), 87.255.8.150:56034->193.37.192.249:52169, len 52
20:30:19 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto UDP, 5.189.183.129:51280->193.37.192.249:52169, len 125
20:30:19 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto TCP (SYN), 95.83.134.107:33935->193.37.192.249:52169, len 52
20:30:19 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto UDP, 87.255.8.150:36848->193.37.192.249:52169, len 48
20:30:19 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto UDP, 95.83.134.107:6414->193.37.192.249:52169, len 48
20:30:19 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto UDP, 5.141.81.19:13638->193.37.192.249:52169, len 132
20:30:19 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto UDP, 94.253.28.224:56866->193.37.192.249:52169, len 131
20:30:19 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto UDP, 5.189.157.90:12006->193.37.192.249:52169, len 125
20:30:19 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto TCP (SYN), 188.243.3.85:63466->193.37.192.249:52169, len 52
20:30:19 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto TCP (SYN), 5.18.243.20:16001->193.37.192.249:52169, len 60
20:30:19 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto TCP (SYN), 152.254.236.46:3794->193.37.192.249:52169, len 48
20:30:19 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto UDP, 109.252.29.115:10035->193.37.192.249:52169, len 48
20:30:19 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto TCP (SYN), 109.252.29.115:16009->193.37.192.249:52169, len 52
20:30:19 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto TCP (SYN), 5.79.98.132:52473->193.37.192.249:52169, len 60
20:30:19 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto UDP, 188.243.3.85:39526->193.37.192.249:52169, len 48
20:30:20 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto TCP (SYN), 89.113.127.231:46439->193.37.192.249:51659, len 52
20:30:20 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto TCP (SYN), 69.159.123.227:61177->193.37.192.249:52169, len 52
20:30:20 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto TCP (SYN), 193.34.217.209:51545->193.37.192.249:52169, len 52
20:30:20 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto TCP (SYN), 79.126.49.44:54133->193.37.192.249:52169, len 52
20:30:20 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto UDP, 79.126.49.44:53354->193.37.192.249:52169, len 48
20:30:20 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto TCP (SYN), 46.72.31.90:42171->193.37.192.249:52169, len 60
20:30:20 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto UDP, 176.8.22.201:31199->193.37.192.249:52169, len 95
20:30:20 firewall,info input: in:sfp-sfpplus1 out:(unknown 0), src-mac 8c:dc:d4b9:04, proto TCP (SYN), 77.40.2.61:22271->193.37.192.249:52169, len 52
action=add-src-to-address-list address-list=port_scanners address-list-timeout=2w chain=input comment="Port scanners to list" protocol=tcp psd=21,3s,3,1 src-address-list=!LAN
action=add-src-to-address-list address-list=port_scanners address-list-timeout=2w chain=input comment="NMAP FIN Stealth scan" protocol=tcp tcp-flags=fin,!syn,!rst,!psh,!ack,!urg
action=add-src-to-address-list address-list=port_scanners address-list-timeout=2w chain=input comment="SYN/FIN scan" protocol=tcp tcp-flags=fin,syn
action=add-src-to-address-list address-list=port_scanners address-list-timeout=2w chain=input comment="SYN/RST scan" protocol=tcp tcp-flags=syn,rst
action=add-src-to-address-list address-list=port_scanners address-list-timeout=2w chain=input comment="FIN/PSH/URG scan" protocol=tcp tcp-flags=fin,psh,urg,!syn,!rst,!ack
action=add-src-to-address-list address-list=port_scanners address-list-timeout=2w chain=input comment="ALL/ALL scan" protocol=tcp tcp-flags=fin,syn,rst,psh,ack,urg
action=add-src-to-address-list address-list=port_scanners address-list-timeout=2w chain=input comment="NMAP NULL scan" protocol=tcp tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg