cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Highlighted
Aspiring Expert
564 Views
Message 1 of 3

concerning firewall events then connection drops on HH2

Hi ,

 

really grateful if someone could explain the sequence of events listed below. It seems to me there is firewall activity (changes?) then the connection drops?. Used to seeing Firwall events such as created /deleted rules after a restart etc..not before???.  Also, like to know what are all these rule changes /deletions that go on?.  Who /what intiated these changes below ..there are no messages to say that my hub is communicating with anything.

 

 

Concerns me that I get these firewall messages flagged up ...............then connection drops.

Thanks guys.

 

21:51:16   16 Jul

CONFIGURATION   saved by TR69

21:50:47   16 Jul

FIREWALL   event (1 of 1): deleted rules

21:50:47   16 Jul

PPP link up (Internet) [217.xxxxxxxx]

21:50:47   16 Jul

FIREWALL event (1 of 14): modified rules

21:50:47   16 Jul

FIREWALL   event (1 of 1): created rules

21:50:47   16 Jul

PPP   CHAP Chap receive success : authentication ok

21:50:47   16 Jul

PPP   CHAP Receive challenge (rhost = ESR13.Birmingham6)

21:50:27   16 Jul

PPP   link down (Internet) [81.xxxxx]

21:49:40   16 Jul

FIREWALL   event (1 of 33): created rules

21:49:40   16 Jul

FIREWALL   event (1 of 7): deleted rules

21:15:05   16 Jul

SNTP   Synchronised again to server: 213.123.26.170

21:11:13   16 Jul

CONFIGURATION   saved by TR69

20:15:05   16 Jul

SNTP   Synchronised again to server: 213.123.26.170

20:02:49   16 Jul

IDS   scan parser : udp port scan: 2.97.134.135 scanned at least 20 ports at   81.xxxx (1 of 1) : 2.97.134.135 81.154.36.185 0056 UDP 16613->61710

19:15:05   16 Jul

SNTP   Synchronised again to server: 213.123.26.170

0 Ratings
2 REPLIES 2
Highlighted
Contributor
556 Views
Message 2 of 3

Re: concerning firewall events then connection drops on HH2

20:02:49   16 Jul

IDS   scan parser : udp port scan: 2.97.134.135 scanned at least 20 ports at   81.xxxx (1 of 1) : 2.97.134.135 81.154.36.185 0056 UDP 16613->61710

Is a port scan by a remote person looking for a way into your system. It's nothing to worry about as most people get these from time to time and your firewall has stopped it. The rest looks OK.

0 Ratings
Highlighted
Aspiring Expert
548 Views
Message 3 of 3

Re: concerning firewall events then connection drops on HH2

Thanks,

what im puzzled about more is the fact  that I have these "firewall events" (rather than the scan) ie the "changes" - then connection drops. Also, from my looking on the web ,forums etc - I seem to have a very large number of rule changes /deletions etc   "1 of 33" "1 of 14" etc when compred to others.....................finally, why did my hub just randomly alter /change these rules???

0 Ratings