NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

urzaseye's avatar
Aug 23, 2016
Status:
Unspecified

log VPN activity

I've got my R8500 (latest firmware -- 1.0.2.64_1.0.6.2) set to automatically email me the system log every day. And it works just fine -- but I've got an all-or-nothing issue with what I get. As an example, here are the first few lines from yesterday's logs (although I redacted my IP address from the OpenVPN lines):

 

[DHCP IP: (10.8.108.5)] to MAC address F2:81:C9:00:88:78, Monday, Aug 08,2016 05:49:27
[OpenVPN, connection successfully]IP address:xxx.xxx.xxx.xxx Monday, Aug 08,2016 05:49:12
[DHCP IP: (10.8.108.4)] to MAC address F6:68:73:A4:27:74, Monday, Aug 08,2016 05:46:24
[OpenVPN, connection successfully]IP address:xxx.xxx.xxx.xxx Monday, Aug 08,2016 05:46:09
[DHCP IP: (10.8.108.76)] to MAC address 84:8E:0C:94:C4:FE, Monday, Aug 08,2016 03:39:39
[DHCP IP: (10.8.108.50)] to MAC address 70:56:81:EC:E5:3C, Monday, Aug 08,2016 03:12:55
[DHCP IP: (10.8.108.75)] to MAC address FC:FC:48:9D:F9:58, Monday, Aug 08,2016 03:03:03
[DoS attack: (null)] (-1086633492) attack packets in last 20 sec from ip [98.129.185.1], Monday, Aug 08,2016 02:14:13

 

I could care less about the DHCP items -- some people may care, but I don't. However, I do care about the DoS attack and the OpenVPN line items. The problem is that inclusion of both the DHCP and OpenVPN items are included under one checkbox -- "router operation (startup, get time, etc.)". I think that DHCP, router startup and getting the time should all fall under "router operation" but VPN activity should be tracked separately. If it's not configurable as its own line item, it would be better bundled with "known DoS attacks and port scans" under the combined header of "security". The way it's setup now, my option is to get logs of VPN activity but only buried within 20x times as many lines about DHCP activity.

No CommentsBe the first to comment