Rispondere

Problema strano log e continue disconnessioni da internet

aletrento
Aspirant

Problema strano log e continue disconnessioni da internet

Buongiorno, ho avuto varie disconnessioni della rete ieri, disconnessioni che non erano dovute alla connettività esterna del fornitore di servizi internet (ho 4 linee di gestori diverse collegati sulla wan). 

Visto che negli ultimi 4 anni non è mai capitata una cosa simile, ho verificato nel log e, putroppo, non ho trovato nulla se non queste attività del kernel.

In ufficio, per via delle festività, non c'era nessuno collegato alla rete, se non alcuni server.

Qualcuno può dirmi se è normale o se devo supporre un attacco esterno?

In particolar modo, cosa significano le righe (ne metto solo alcune, ma in realtà ci sarebbero 10 pagine di righe simili generate tutte nello stesso intervallo di tempo):

 

Tue Jan  1 23:14:05 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_get(tp a80000041e535980,handle 0x00000000)

Wed Jan  2 01:52:51 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] HTB: quantum of class 10001 is big. Consider r2q change.

Wed Jan  2 01:52:46 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] HTB: quantum of class 10001 is big. Consider r2q change.

Wed Jan  2 01:52:16 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: no IPv6 routers present

Wed Jan  2 01:52:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: add 33:33:ff:28:cc:56 mcast address to master interface

Wed Jan  2 01:52:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: add 01:00:5e:00:00:01 mcast address to master interface

Wed Jan  2 01:52:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: add 33:33:00:00:00:01 mcast address to master interface

Wed Jan  2 01:52:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: Setting MAC address to  e4 f4 c6 28 cc 56.

Wed Jan  2 01:52:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] IPsec: device unregistering: eth0.3

Wed Jan  2 01:52:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] IPsec: device down: eth0.3

Wed Jan  2 01:52:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: del 33:33:00:00:00:01 mcast address from master interface

Wed Jan  2 01:52:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: del 33:33:00:00:00:01 mcast address from vlan interface

Wed Jan  2 01:52:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: del 01:00:5e:00:00:01 mcast address from master interface

Wed Jan  2 01:52:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: del 01:00:5e:00:00:01 mcast address from vlan interface

Wed Jan  2 01:52:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: del 33:33:ff:28:cc:56 mcast address from master interface

Wed Jan  2 01:52:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: del 33:33:ff:28:cc:56 mcast address from vlan interface

Wed Jan  2 01:52:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: add 33:33:ff:28:cc:56 mcast address to master interface

Wed Jan  2 01:52:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: add 01:00:5e:00:00:01 mcast address to master interface

Wed Jan  2 01:52:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: add 33:33:00:00:00:01 mcast address to master interface

Wed Jan  2 01:52:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: Setting MAC address to  e4 f4 c6 28 cc 56.

Wed Jan  2 01:52:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] IPsec: device unregistering: eth0.3

Wed Jan  2 01:52:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] IPsec: device down: eth0.3

Wed Jan  2 01:52:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: del 33:33:00:00:00:01 mcast address from master interface

Wed Jan  2 01:52:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: del 33:33:00:00:00:01 mcast address from vlan interface

Wed Jan  2 01:52:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: del 01:00:5e:00:00:01 mcast address from master interface

Wed Jan  2 01:52:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: del 01:00:5e:00:00:01 mcast address from vlan interface

Wed Jan  2 01:52:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: del 33:33:ff:28:cc:56 mcast address from master interface

Wed Jan  2 01:52:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: del 33:33:ff:28:cc:56 mcast address from vlan interface

Wed Jan  2 01:51:56 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: no IPv6 routers present

Wed Jan  2 01:51:46 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: add 33:33:ff:28:cc:56 mcast address to master interface

Wed Jan  2 01:51:46 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: add 01:00:5e:00:00:01 mcast address to master interface

Wed Jan  2 01:51:46 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: add 33:33:00:00:00:01 mcast address to master interface

Wed Jan  2 01:51:46 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: Setting MAC address to  e4 f4 c6 28 cc 56.

Wed Jan  2 01:51:46 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] IPsec: device unregistering: eth0.3

Wed Jan  2 01:51:46 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] IPsec: device down: eth0.3

Wed Jan  2 01:51:46 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: del 33:33:00:00:00:01 mcast address from master interface

Wed Jan  2 01:51:46 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: del 33:33:00:00:00:01 mcast address from vlan interface

Wed Jan  2 01:51:46 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: del 01:00:5e:00:00:01 mcast address from master interface

Wed Jan  2 01:51:46 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: del 01:00:5e:00:00:01 mcast address from vlan interface

Wed Jan  2 01:51:46 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: del 33:33:ff:28:cc:56 mcast address from master interface

Wed Jan  2 01:51:46 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: del 33:33:ff:28:cc:56 mcast address from vlan interface

Wed Jan  2 01:51:46 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: add 33:33:ff:28:cc:56 mcast address to master interface

Wed Jan  2 01:51:46 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: add 01:00:5e:00:00:01 mcast address to master interface

Wed Jan  2 01:51:46 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: add 33:33:00:00:00:01 mcast address to master interface

Wed Jan  2 01:51:46 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: Setting MAC address to  e4 f4 c6 28 cc 56.

Wed Jan  2 01:51:46 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] IPsec: device unregistering: eth0.3

Wed Jan  2 01:51:46 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] IPsec: device down: eth0.3

Wed Jan  2 01:51:46 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: del 33:33:00:00:00:01 mcast address from master interface

Wed Jan  2 01:51:46 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: del 33:33:00:00:00:01 mcast address from vlan interface

Wed Jan  2 01:51:46 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: del 01:00:5e:00:00:01 mcast address from master interface

Wed Jan  2 01:51:46 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: del 01:00:5e:00:00:01 mcast address from vlan interface

Wed Jan  2 01:51:46 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: del 33:33:ff:28:cc:56 mcast address from master interface

Wed Jan  2 01:51:46 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] eth0.3: del 33:33:ff:28:cc:56 mcast address from vlan interface

Wed Jan  2 01:51:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] HTB: quantum of class 11024 is big. Consider r2q change.

Wed Jan  2 01:51:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] HTB: quantum of class 10001 is big. Consider r2q change.

Wed Jan  2 01:51:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] p->perfect 0000000000000000 p->h a80000041884fc00

Wed Jan  2 01:51:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_dump(tp a80000041e4f1e80,fh 0x0,skb a80000041ea2b980,t a80000041757f010),p a8000004186b1b00,r 0000000000000000,b a80000041757f038

Wed Jan  2 01:51:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_change(tp a80000041e4f1e80,handle 0x00000000,tca a80000041fc38a80,arg a8000004168ab950),opt a800000417da3430,p a8000004186b1b00,r 0000000000000000,*arg 0x0

Wed Jan  2 01:51:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_get(tp a80000041e4f1e80,handle 0x00000000)

Wed Jan  2 01:51:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_init(tp a80000041e4f1e80)

Wed Jan  2 01:51:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_delete(tp a80000041e4f1e80,arg 0xa8000004186b1508),p a8000004186b1b00,f 0000000000000000

Wed Jan  2 01:51:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_walk(tp a80000041e4f1e80,walker a800000417217900),p a8000004186b1b00

Wed Jan  2 01:51:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_destroy(tp a80000041e4f1e80),p a8000004186b1b00

Wed Jan  2 01:50:21 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] HTB: quantum of class 11024 is big. Consider r2q change.

Wed Jan  2 01:50:21 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] HTB: quantum of class 10001 is big. Consider r2q change.

Wed Jan  2 01:50:21 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] p->perfect 0000000000000000 p->h a800000417da3400

Wed Jan  2 01:50:21 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_dump(tp a80000041e4f1e80,fh 0x0,skb a800000418b0c680,t a8000004172e0010),p a8000004186b1b00,r 0000000000000000,b a8000004172e0038

Wed Jan  2 01:50:21 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_change(tp a80000041e4f1e80,handle 0x00000000,tca a80000041fc38a80,arg a8000004179ff950),opt a800000417da3630,p a8000004186b1b00,r 0000000000000000,*arg 0x0

Wed Jan  2 01:50:21 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_get(tp a80000041e4f1e80,handle 0x00000000)

Wed Jan  2 01:50:21 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_init(tp a80000041e4f1e80)

Wed Jan  2 01:50:21 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_delete(tp a80000041e4f1e80,arg 0xa8000004186b1508),p a8000004186b1b00,f 0000000000000000

Wed Jan  2 01:50:21 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_walk(tp a80000041e4f1e80,walker a8000004168ab900),p a8000004186b1b00

Wed Jan  2 01:50:21 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_destroy(tp a80000041e4f1e80),p a8000004186b1b00

Wed Jan  2 01:49:31 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] HTB: quantum of class 11024 is big. Consider r2q change.

Wed Jan  2 01:49:31 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] HTB: quantum of class 10001 is big. Consider r2q change.

Wed Jan  2 01:49:31 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] p->perfect 0000000000000000 p->h a800000417da3600

Wed Jan  2 01:49:31 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_dump(tp a80000041e4f1e80,fh 0x0,skb a800000418b0cb00,t a800000416778010),p a8000004186b1b00,r 0000000000000000,b a800000416778038

Wed Jan  2 01:49:31 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_change(tp a80000041e4f1e80,handle 0x00000000,tca a80000041fc38a80,arg a800000417ce3950),opt a800000418fae030,p a8000004186b1b00,r 0000000000000000,*arg 0x0

Wed Jan  2 01:49:31 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_get(tp a80000041e4f1e80,handle 0x00000000)

Wed Jan  2 01:49:31 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_init(tp a80000041e4f1e80)

Wed Jan  2 01:49:31 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_delete(tp a80000041e4f1e80,arg 0xa8000004186b1508),p a8000004186b1b00,f 0000000000000000

Wed Jan  2 01:49:31 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_walk(tp a80000041e4f1e80,walker a80000041695f900),p a8000004186b1b00

Wed Jan  2 01:49:31 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_destroy(tp a80000041e4f1e80),p a8000004186b1b00

Wed Jan  2 01:48:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] HTB: quantum of class 11024 is big. Consider r2q change.

Wed Jan  2 01:48:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] HTB: quantum of class 10001 is big. Consider r2q change.

Wed Jan  2 01:48:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] p->perfect 0000000000000000 p->h a800000418fae000

Wed Jan  2 01:48:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_dump(tp a80000041e4f1e80,fh 0x0,skb a800000416d74080,t a8000004174b3010),p a8000004186b1b00,r 0000000000000000,b a8000004174b3038

Wed Jan  2 01:48:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_change(tp a80000041e4f1e80,handle 0x00000000,tca a80000041fc38a80,arg a80000041826f950),opt a800000417da3230,p a8000004186b1b00,r 0000000000000000,*arg 0x0

Wed Jan  2 01:48:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_get(tp a80000041e4f1e80,handle 0x00000000)

Wed Jan  2 01:48:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_init(tp a80000041e4f1e80)

Wed Jan  2 01:48:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_delete(tp a800000416ee3880,arg 0xa80000041ea6b608),p a80000041e4f1e80,f 0000000000000000

Wed Jan  2 01:48:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_walk(tp a800000416ee3880,walker a800000417bf7900),p a80000041e4f1e80

Wed Jan  2 01:48:06 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_destroy(tp a800000416ee3880),p a80000041e4f1e80

Wed Jan  2 01:45:36 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] HTB: quantum of class 11024 is big. Consider r2q change.

Wed Jan  2 01:45:36 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] HTB: quantum of class 10001 is big. Consider r2q change.

Wed Jan  2 01:45:36 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] p->perfect 0000000000000000 p->h a800000418fae000

Wed Jan  2 01:45:36 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_dump(tp a800000416ee3880,fh 0x0,skb a800000416f23800,t a800000417680010),p a80000041e4f1e80,r 0000000000000000,b a800000417680038

Wed Jan  2 01:45:36 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_change(tp a800000416ee3880,handle 0x00000000,tca a80000041fc38a80,arg a8000004167ef950),opt a800000417da3430,p a80000041e4f1e80,r 0000000000000000,*arg 0x0

Wed Jan  2 01:45:36 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_get(tp a800000416ee3880,handle 0x00000000)

Wed Jan  2 01:45:36 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_init(tp a800000416ee3880)

Wed Jan  2 01:45:36 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_delete(tp a800000416ee3880,arg 0xa80000041ea6b608),p a80000041e4f1e80,f 0000000000000000

Wed Jan  2 01:45:36 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_walk(tp a800000416ee3880,walker a800000417283900),p a80000041e4f1e80

Wed Jan  2 01:45:36 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] tcindex_destroy(tp a800000416ee3880),p a80000041e4f1e80

Wed Jan  2 01:44:56 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] HTB: quantum of class 11024 is big. Consider r2q change.

Wed Jan  2 01:44:56 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] HTB: quantum of class 10001 is big. Consider r2q change.

Wed Jan  2 01:44:56 2019((GMT+0100)) [SRX5308][Kernel][KERNEL] p->perfect 0000000000000000 p->h a800000417da3400

 

Fatemi sapere per favore se il router è stato compromesso, oppure se posso stare tranquillo. Se questo modello a vostro avviso è da sostituire con qualcosa di più nuovo e sicuro, ditemelo perchè la sicurezza per me è fondamentale.

 

Grazie,

Alessio.

Model: SRX5308|PROSAFE Gigabit Quad WAN SSL & IPSEC VPN Firewall
Messaggio 1 di 4
FedericoG
NETGEAR Employee Retired

Re: Problema strano log e continue disconnessioni da internet

Gentile @aletrento,
Benvenuto nella Community!

 

Le consigliamo di contattare il supporto tecnico per approfondire.
http://www.netgear.it/support/contact.aspx


Saluti
Federico
Team NETGEAR
 

 

Messaggio 2 di 4
aletrento
Aspirant

Re: Problema strano log e continue disconnessioni da internet

Grazie, però mi chiede il numero di serie e sono fuori sede in ferie questi giorni. Secondo te riesco a contattare l'assistenza anche senza seriale? Per come hai potuto visionare il log, mi consigli di intervenire tempestivamente o posso stare tranquillo fino all'8 gennaio?

Messaggio 3 di 4
FedericoG
NETGEAR Employee Retired

Re: Problema strano log e continue disconnessioni da internet

Gentile @aletrento,

Le ho inoltrato un messaggio privato con le indicazioni su come contattare l'assistenza.

Saluti
Federico

Team NETGEAR

Messaggio 4 di 4
Statistiche discussione
  • 3 risposte
  • 1188 visualizzazioni
  • 0 kudos
  • 2 con conversazione attiva