Temat: banIP
Witam!
od jakiegoś czasu ktoś próbuje dostać się do mojej sieci więc zainstalowałem banIP, ale mam mały problem z zablokowaniem pewnego MAC-a
tak wygląda fragment dziennika zapory:
Sat Feb 15 21:10:06 2025 kern.warn kernel: [3010969.311650] banIP/fwd-wan/drop/blocklistv4: IN=eth0.2 OUT=br-lan MAC=1c:3b:f3:50:29:7c:b8:a3:77:e3:fd:6c:08:00:45:00:00:3c SRC=87.236.176.26 DST=192.168.1.43 LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=8946 DF PROTO=TCP SPT=60051 DPT=80 WINDOW=64240 RES=0x00 SYN URGP=0
Sat Feb 15 21:10:09 2025 kern.warn kernel: [3010972.357240] banIP/fwd-wan/drop/blocklistv4: IN=eth0.2 OUT=br-lan MAC=1c:3b:f3:50:29:7c:b8:a3:77:e3:fd:6c:08:00:45:00:00:3c SRC=87.236.176.26 DST=192.168.1.43 LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=8948 DF PROTO=TCP SPT=60051 DPT=80 WINDOW=64240 RES=0x00 SYN URGP=0
Sat Feb 15 21:10:13 2025 kern.warn kernel: [3010976.658140] banIP/fwd-wan/drop/blocklistv4: IN=eth0.2 OUT=br-lan MAC=1c:3b:f3:50:29:7c:b8:a3:77:e3:fd:6c:08:00:45:00:00:3c SRC=45.55.186.92 DST=192.168.1.43 LEN=60 TOS=0x00 PREC=0x00 TTL=51 ID=41462 DF PROTO=TCP SPT=39887 DPT=80 WINDOW=65535 RES=0x00 SYN URGP=0
Sat Feb 15 21:10:14 2025 kern.warn kernel: [3010977.678932] banIP/fwd-wan/drop/blocklistv4: IN=eth0.2 OUT=br-lan MAC=1c:3b:f3:50:29:7c:b8:a3:77:e3:fd:6c:08:00:45:00:00:3c SRC=45.55.186.92 DST=192.168.1.43 LEN=60 TOS=0x00 PREC=0x00 TTL=51 ID=41463 DF PROTO=TCP SPT=39887 DPT=80 WINDOW=65535 RES=0x00 SYN URGP=0
Sat Feb 15 21:10:15 2025 kern.warn kernel: [3010978.704055] banIP/fwd-wan/drop/blocklistv4: IN=eth0.2 OUT=br-lan MAC=1c:3b:f3:50:29:7c:b8:a3:77:e3:fd:6c:08:00:45:00:00:3c SRC=45.55.186.92 DST=192.168.1.43 LEN=60 TOS=0x00 PREC=0x00 TTL=51 ID=41464 DF PROTO=TCP SPT=39887 DPT=80 WINDOW=65535 RES=0x00 SYN URGP=0
Sat Feb 15 21:10:16 2025 kern.warn kernel: [3010979.726904] banIP/fwd-wan/drop/blocklistv4: IN=eth0.2 OUT=br-lan MAC=1c:3b:f3:50:29:7c:b8:a3:77:e3:fd:6c:08:00:45:00:00:3c SRC=45.55.186.92 DST=192.168.1.43 LEN=60 TOS=0x00 PREC=0x00 TTL=51 ID=41465 DF PROTO=TCP SPT=39887 DPT=80 WINDOW=65535 RES=0x00 SYN URGP=0
Sat Feb 15 21:10:17 2025 kern.warn kernel: [3010980.751992] banIP/fwd-wan/drop/blocklistv4: IN=eth0.2 OUT=br-lan MAC=1c:3b:f3:50:29:7c:b8:a3:77:e3:fd:6c:08:00:45:00:00:3c SRC=45.55.186.92 DST=192.168.1.43 LEN=60 TOS=0x00 PREC=0x00 TTL=51 ID=41466 DF PROTO=TCP SPT=39887 DPT=80 WINDOW=65535 RES=0x00 SYN URGP=0
Sat Feb 15 21:10:18 2025 kern.warn kernel: [3010981.774953] banIP/fwd-wan/drop/blocklistv4: IN=eth0.2 OUT=br-lan MAC=1c:3b:f3:50:29:7c:b8:a3:77:e3:fd:6c:08:00:45:00:00:3c SRC=45.55.186.92 DST=192.168.1.43 LEN=60 TOS=0x00 PREC=0x00 TTL=51 ID=41467 DF PROTO=TCP SPT=39887 DPT=80 WINDOW=65535 RES=0x00 SYN URGP=0
Sat Feb 15 21:11:33 2025 kern.warn kernel: [3011056.549581] banIP/fwd-wan/drop/blocklistv4: IN=eth0.2 OUT=br-lan MAC=1c:3b:f3:50:29:7c:b8:a3:77:e3:fd:6c:08:00:45:00:00:3c SRC=87.236.176.124 DST=192.168.1.6 LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=39104 DF PROTO=TCP SPT=42655 DPT=21 WINDOW=64240 RES=0x00 SYN URGP=0
Sat Feb 15 21:11:34 2025 kern.warn kernel: [3011057.552784] banIP/fwd-wan/drop/blocklistv4: IN=eth0.2 OUT=br-lan MAC=1c:3b:f3:50:29:7c:b8:a3:77:e3:fd:6c:08:00:45:00:00:3c SRC=87.236.176.124 DST=192.168.1.6 LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=39105 DF PROTO=TCP SPT=42655 DPT=21 WINDOW=64240 RES=0x00 SYN URGP=0
Sat Feb 15 21:11:36 2025 kern.warn kernel: [3011059.568600] banIP/fwd-wan/drop/blocklistv4: IN=eth0.2 OUT=br-lan MAC=1c:3b:f3:50:29:7c:b8:a3:77:e3:fd:6c:08:00:45:00:00:3c SRC=87.236.176.124 DST=192.168.1.6 LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=39106 DF PROTO=TCP SPT=42655 DPT=21 WINDOW=64240 RES=0x00 SYN URGP=0
Sat Feb 15 21:11:40 2025 kern.warn kernel: [3011064.034148] banIP/inp-wan/drop/blocklistv4: IN=eth0.2 OUT= chodzi o to, że mam te adresy IP zablokowane w liście zablokowanych, ale chciałbym zablokować jego MAC tylko że on jak tu widać jest trochę długi.
Jaki adres MAC powinienem zablokować?