cancel
Showing results for 
Search instead for 
Did you mean: 
1

Ask

2

Reply

3

Solution

Pro II hub - Firewall warnings

aidej
3: Seeker
3: Seeker

Hi everyone,

Today for the first time in the year I have had my CityFibre 900mb connection, my connection has dropped at least  5 times and checking the Pro II hub error logs I can see lots of firewall warnings which I haven't noticed before and there seems to be a number of them within a short space of time, which is concerning me.

The source IP address for these seems to vary between Iran, China, Spain and the USA amongst others. Can anyone advise if this is a sign someone is targeting my router? I also have a static IP address (my full static IP address has be masked out below) and wondered if that is related to the warnings at all? Any advice would be welcomed. Thanks.


02/08/2024
17:02:56
DROP wan in: IN=pppoe-wan OUT= MAC= src=120.29.110.44 DST=193.237.xxx.x LEN=48 TOS=0x00 PREC=0x00 TTL=116 ID=30070 PROTO=UDP SPT=14795 DPT=29782 LEN=28 MARK=0x8000000
firewall
02/08/2024
17:01:56
DROP wan in: IN=pppoe-wan OUT= MAC= src=58.8.19.179 DST=193.237.xxx.x LEN=52 TOS=0x00 PREC=0x00 TTL=108 ID=3138 DF PROTO=TCP SPT=64084 DPT=29782 WINDOW=64240 RES=0x00 SYN URGP=0 MARK=0x8000000
firewall
02/08/2024
17:00:56
DROP wan in: IN=pppoe-wan OUT= MAC= src=23.95.132.51 DST=193.237.xxx.x LEN=40 TOS=0x00 PREC=0x00 TTL=244 ID=9482 PROTO=TCP SPT=42946 DPT=1186 WINDOW=1024 RES=0x00 SYN URGP=0 MARK=0x8000000
firewall
02/08/2024
16:59:56
DROP wan in: IN=pppoe-wan OUT= MAC= src=58.8.19.179 DST=193.237.xxx.x LEN=52 TOS=0x00 PREC=0x00 TTL=108 ID=3127 DF PROTO=TCP SPT=63899 DPT=29782 WINDOW=64240 RES=0x00 SYN URGP=0 MARK=0x8000000
firewall
02/08/2024
16:58:55
DROP wan in: IN=pppoe-wan OUT= MAC= src=45.133.6.93 DST=193.237.xxx.x LEN=52 TOS=0x00 PREC=0x00 TTL=116 ID=44132 DF PROTO=TCP SPT=57228 DPT=29782 WINDOW=65500 RES=0x00 SYN URGP=0 MARK=0x8000000
firewall
02/08/2024
16:57:55
DROP wan in: IN=pppoe-wan OUT= MAC= src=141.98.255.150 DST=193.237.xxx.x LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=2273 DF PROTO=TCP SPT=60542 DPT=29782 WINDOW=8192 RES=0x00 SYN URGP=0 MARK=0x8000000
firewall
02/08/2024
16:56:56
DROP wan in: IN=pppoe-wan OUT= MAC= src=146.70.220.117 DST=193.237.xxx.x LEN=52 TOS=0x00 PREC=0x00 TTL=51 ID=1986 DF PROTO=TCP SPT=49205 DPT=29782 WINDOW=42340 RES=0x00 SYN URGP=0 MARK=0x8000000
firewall
02/08/2024
16:55:58
DROP wan in: IN=pppoe-wan OUT= MAC= src=180.191.162.57 DST=193.237.xxx.x LEN=64 TOS=0x00 PREC=0x00 TTL=50 ID=0 DF PROTO=TCP SPT=55120 DPT=29782 WINDOW=65535 RES=0x00 SYN URGP=0 MARK=0x8000000
firewall
02/08/2024
16:54:56
DROP wan in: IN=pppoe-wan OUT= MAC= src=5.189.157.90 DST=193.237.xxx.x LEN=125 TOS=0x00 PREC=0x00 TTL=58 ID=18406 DF PROTO=UDP SPT=12057 DPT=29782 LEN=105 MARK=0x8000000
firewall
02/08/2024
16:53:58
DROP wan in: IN=pppoe-wan OUT= MAC= src=189.203.6.253 DST=193.237.xxx.x LEN=134 TOS=0x00 PREC=0x00 TTL=106 ID=38123 PROTO=UDP SPT=28715 DPT=37289 LEN=114 MARK=0x8000000
firewall

4 REPLIES 4

Ripshod
16: Advanced member
16: Advanced member

Everyone experiences these probes from wannabe hackers, learning from the lower rung. Just consider it background radiation. The "DROP" shows the firewall has done its job. 

Cynric
16: Advanced member
16: Advanced member

@aidej If you have time you can always lookup the src IP address here ---> https://www.abuseipdb.com and see who is being nosey. 

CrimsonLiar
16: Advanced member
16: Advanced member

Just to clarify, those entries in your logs indicate that the router dropped an unsolicited incoming connection from a specific IP address.  Your connection with the internet as a whole did not drop in those instances.

aidej
3: Seeker
3: Seeker

Thanks for all the helpful advice everyone, much appreciated!