Here's a small sample:
On the time dimension it's not really a "flood" since items appear only every few seconds, not continuously. Still, it makes for huge blocks of these items when the log is opened for viewing. Because of the "kernel" I'm guessing it's the built-in firewall generating them. Regardless, unless they're useful in some way I should know about, I'd like to know if they can be suppressed.
I have the same question about these items:
I don't have even a guess as to what's generating those, but the MAC is that of my iPhone.
Code:
Aug 11 04:37:38 kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=34:a3:95:8c:4b:38:00:01:5c:9d:b2:46:08:00 SRC=139.59.58.115 DST=47.33.58.100 LEN=40 TOS=0x00 PREC=0x00 TTL=234 ID=13715 PROTO=TCP SPT=42091 DPT=20183 SEQ=3722723616 ACK=0 WINDOW=1024 RES=0x00 SYN URGP=0 MARK=0x8000000
Aug 11 04:37:50 kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=34:a3:95:8c:4b:38:00:01:5c:9d:b2:46:08:00 SRC=45.129.33.5 DST=47.33.58.100 LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=60398 PROTO=TCP SPT=48293 DPT=51080 SEQ=2417366530 ACK=0 WINDOW=1024 RES=0x00 SYN URGP=0 MARK=0x8000000
Aug 11 04:37:59 kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=34:a3:95:8c:4b:38:00:01:5c:9d:b2:46:08:00 SRC=45.129.33.152 DST=47.33.58.100 LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=61517 PROTO=TCP SPT=51989 DPT=9851 SEQ=687991890 ACK=0 WINDOW=1024 RES=0x00 SYN URGP=0 MARK=0x8000000
Aug 11 04:38:02 kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=34:a3:95:8c:4b:38:00:01:5c:9d:b2:46:08:00 SRC=138.68.94.142 DST=47.33.58.100 LEN=40 TOS=0x00 PREC=0x00 TTL=239 ID=42557 PROTO=TCP SPT=50861 DPT=28331 SEQ=3920687858 ACK=0 WINDOW=1024 RES=0x00 SYN URGP=0 MARK=0x8000000
Aug 11 04:38:10 kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=34:a3:95:8c:4b:38:00:01:5c:9d:b2:46:08:00 SRC=223.71.167.163 DST=47.33.58.100 LEN=44 TOS=0x00 PREC=0x00 TTL=110 ID=41064 PROTO=TCP SPT=23032 DPT=5800 SEQ=3398061016 ACK=0 WINDOW=29200 RES=0x00 SYN URGP=0 OPT (020405B4) MARK=0x8000000
Aug 11 04:38:13 kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=34:a3:95:8c:4b:38:00:01:5c:9d:b2:46:08:00 SRC=106.12.70.112 DST=47.33.58.100 LEN=40 TOS=0x00 PREC=0x00 TTL=233 ID=17167 PROTO=TCP SPT=53864 DPT=1485 SEQ=4037115046 ACK=0 WINDOW=1024 RES=0x00 SYN URGP=0 MARK=0x8000000
Aug 11 04:38:13 kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=34:a3:95:8c:4b:38:00:01:5c:9d:b2:46:08:00 SRC=45.145.67.14 DST=47.33.58.100 LEN=40 TOS=0x00 PREC=0x00 TTL=239 ID=59297 PROTO=TCP SPT=44940 DPT=4160 SEQ=1540410757 ACK=0 WINDOW=1024 RES=0x00 SYN URGP=0 MARK=0x8000000
Aug 11 04:38:15 kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=34:a3:95:8c:4b:38:00:01:5c:9d:b2:46:08:00 SRC=159.65.154.48 DST=47.33.58.100 LEN=40 TOS=0x00 PREC=0x00 TTL=234 ID=34191 PROTO=TCP SPT=52388 DPT=15608 SEQ=883524371 ACK=0 WINDOW=1024 RES=0x00 SYN URGP=0 MARK=0x8000000
Aug 11 04:38:25 kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=34:a3:95:8c:4b:38:00:01:5c:9d:b2:46:08:00 SRC=193.93.62.61 DST=47.33.58.100 LEN=40 TOS=0x00 PREC=0x00 TTL=239 ID=40347 PROTO=TCP SPT=41953 DPT=7799 SEQ=2260908424 ACK=0 WINDOW=1024 RES=0x00 SYN URGP=0 MARK=0x8000000
Aug 11 04:38:33 kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=34:a3:95:8c:4b:38:00:01:5c:9d:b2:46:08:00 SRC=51.91.158.178 DST=47.33.58.100 LEN=40 TOS=0x00 PREC=0x00 TTL=237 ID=1043 PROTO=TCP SPT=43958 DPT=15332 SEQ=3168732563 ACK=0 WINDOW=1024 RES=0x00 SYN URGP=0 MARK=0x8000000
I have the same question about these items:
Code:
Aug 11 04:29:12 wlceventd: WLCEVENTD wlceventd_proc_event(466): eth5: Deauth_ind 7C:A1:AE:C3:4E:6C, status: 0, reason: Class 3 frame received from nonassociated station (7)
Aug 11 04:29:12 wlceventd: WLCEVENTD wlceventd_proc_event(466): eth5: Deauth_ind 7C:A1:AE:C3:4E:6C, status: 0, reason: Class 2 frame received from nonauthenticated station (6)
Aug 11 04:29:12 wlceventd: WLCEVENTD wlceventd_proc_event(466): eth5: Deauth_ind 7C:A1:AE:C3:4E:6C, status: 0, reason: Class 3 frame received from nonassociated station (7)
Aug 11 04:29:12 wlceventd: WLCEVENTD wlceventd_proc_event(466): eth5: Deauth_ind 7C:A1:AE:C3:4E:6C, status: 0, reason: Class 3 frame received from nonassociated station (7)
Aug 11 04:29:12 wlceventd: WLCEVENTD wlceventd_proc_event(466): eth5: Deauth_ind 7C:A1:AE:C3:4E:6C, status: 0, reason: Class 3 frame received from nonassociated station (7)
Aug 11 04:29:13 wlceventd: WLCEVENTD wlceventd_proc_event(466): eth5: Deauth_ind 7C:A1:AE:C3:4E:6C, status: 0, reason: Class 3 frame received from nonassociated station (7)
Aug 11 04:29:13 wlceventd: WLCEVENTD wlceventd_proc_event(466): eth5: Deauth_ind 7C:A1:AE:C3:4E:6C, status: 0, reason: Class 3 frame received from nonassociated station (7)
Aug 11 04:29:13 wlceventd: WLCEVENTD wlceventd_proc_event(466): eth5: Deauth_ind 7C:A1:AE:C3:4E:6C, status: 0, reason: Class 2 frame received from nonauthenticated station (6)
Aug 11 04:29:13 wlceventd: WLCEVENTD wlceventd_proc_event(466): eth5: Deauth_ind 7C:A1:AE:C3:4E:6C, status: 0, reason: Class 3 frame received from nonassociated station (7)
Aug 11 04:29:13 wlceventd: WLCEVENTD wlceventd_proc_event(466): eth5: Deauth_ind 7C:A1:AE:C3:4E:6C, status: 0, reason: Class 3 frame received from nonassociated station (7)
Aug 11 04:29:13 wlceventd: WLCEVENTD wlceventd_proc_event(466): eth5: Deauth_ind 7C:A1:AE:C3:4E:6C, status: 0, reason: Class 3 frame received from nonassociated station (7)