I've installed and been learning Skynet for some days now, there is one thing in the logs that I can't figure out how to read / interpret.
Skynet blocks outbounds, but all I can see been blocked seems to be originating from the router itself. For example, here the three most blocked out bound IPs:
How can I read this? It is router trying to make those connection or do they come from the LAN but the device is unidentified for some reason?
How can I further diagnose what's going on with those outbound connections? Like, how/where are they starting.
I'm using an AXE16000 with Merlin.
Thanks for your help.
Skynet blocks outbounds, but all I can see been blocked seems to be originating from the router itself. For example, here the three most blocked out bound IPs:
Code:
10 Most Recent Blocks From 147.78.47.176;
May 9 02:40:59 kernel: [BLOCKED - INBOUND] IN=ppp0 OUT= MAC= SRC=147.78.47.176 DST=x.x.x.x LEN=40 TOS=0x00 PREC=0x00 TTL=248 ID=7633 PROTO=TCP SPT=54367 DPT=8443 SEQ=4149757245 ACK=0 WINDOW=1024 RES
May 9 02:52:02 kernel: [BLOCKED - INBOUND] IN=ppp0 OUT= MAC= SRC=147.78.47.176 DST=x.x.x.x LEN=40 TOS=0x00 PREC=0x00 TTL=248 ID=34187 PROTO=TCP SPT=55449 DPT=8080 SEQ=4097106444 ACK=0 WINDOW=1024 RE
May 9 03:08:00 kernel: [BLOCKED - OUTBOUND] IN= OUT=ppp1 SRC=192.168.2.1 DST=147.78.47.176 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=TCP SPT=8443 DPT=56529 SEQ=2863673844 ACK=2490895678 WINDOW=65340
May 9 03:08:01 kernel: [BLOCKED - OUTBOUND] IN= OUT=ppp1 SRC=192.168.2.1 DST=147.78.47.176 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=TCP SPT=8443 DPT=56529 SEQ=2863673844 ACK=2490895678 WINDOW=65340
May 9 05:48:25 kernel: [BLOCKED - INBOUND] IN=ppp0 OUT= MAC= SRC=147.78.47.176 DST=x.x.x.x LEN=40 TOS=0x00 PREC=0x00 TTL=248 ID=44864 PROTO=TCP SPT=45749 DPT=8080 SEQ=2287257799 ACK=0 WINDOW=1024 RE
May 9 07:14:43 kernel: [BLOCKED - INBOUND] IN=ppp0 OUT= MAC= SRC=147.78.47.176 DST=x.x.x.x LEN=40 TOS=0x00 PREC=0x00 TTL=248 ID=33528 PROTO=TCP SPT=50944 DPT=8443 SEQ=4225096212 ACK=0 WINDOW=1024 RE
May 9 07:27:19 kernel: [BLOCKED - INBOUND] IN=ppp0 OUT= MAC= SRC=147.78.47.176 DST=x.x.x.x LEN=40 TOS=0x00 PREC=0x00 TTL=248 ID=34292 PROTO=TCP SPT=52027 DPT=8080 SEQ=686809715 ACK=0 WINDOW=1024 RES
May 9 07:40:30 kernel: [BLOCKED - OUTBOUND] IN= OUT=ppp1 SRC=192.168.2.1 DST=147.78.47.176 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=TCP SPT=8443 DPT=53107 SEQ=301263442 ACK=2454046790 WINDOW=65340 R
May 9 07:40:31 kernel: [BLOCKED - OUTBOUND] IN= OUT=ppp1 SRC=192.168.2.1 DST=147.78.47.176 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=TCP SPT=8443 DPT=53107 SEQ=301263442 ACK=2454046790 WINDOW=65340 R
May 9 10:27:39 kernel: [BLOCKED - INBOUND] IN=ppp0 OUT= MAC= SRC=147.78.47.176 DST=x.x.x.x LEN=40 TOS=0x00 PREC=0x00 TTL=248 ID=38528 PROTO=TCP SPT=42321 DPT=8080 SEQ=3623088391 ACK=0 WINDOW=1024 RE
Code:
10 Most Recent Blocks From 23.95.186.183;
May 8 16:37:13 kernel: [BLOCKED - OUTBOUND] IN= OUT=ppp0 SRC=192.168.2.1 DST=23.95.186.183 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=TCP SPT=8443 DPT=58656 SEQ=3343650615 ACK=780480555 WINDOW=65340 R
May 8 16:37:14 kernel: [BLOCKED - OUTBOUND] IN= OUT=ppp0 SRC=192.168.2.1 DST=23.95.186.183 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=TCP SPT=8443 DPT=58656 SEQ=3343650615 ACK=780480555 WINDOW=65340 R
May 8 21:19:50 kernel: [BLOCKED - OUTBOUND] IN= OUT=ppp0 SRC=192.168.2.1 DST=23.95.186.183 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=TCP SPT=8443 DPT=55285 SEQ=4061687358 ACK=1267577594 WINDOW=65340
May 8 21:19:51 kernel: [BLOCKED - OUTBOUND] IN= OUT=ppp0 SRC=192.168.2.1 DST=23.95.186.183 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=TCP SPT=8443 DPT=55285 SEQ=4061687358 ACK=1267577594 WINDOW=65340
May 9 01:53:52 kernel: [BLOCKED - OUTBOUND] IN= OUT=ppp0 SRC=192.168.2.1 DST=23.95.186.183 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=TCP SPT=8443 DPT=52207 SEQ=1325613638 ACK=2060921360 WINDOW=65340
May 9 01:53:53 kernel: [BLOCKED - OUTBOUND] IN= OUT=ppp0 SRC=192.168.2.1 DST=23.95.186.183 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=TCP SPT=8443 DPT=52207 SEQ=1325613638 ACK=2060921360 WINDOW=65340
May 9 06:29:46 kernel: [BLOCKED - OUTBOUND] IN= OUT=ppp0 SRC=192.168.2.1 DST=23.95.186.183 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=TCP SPT=8443 DPT=48308 SEQ=173238269 ACK=1950839580 WINDOW=65340 R
May 9 06:29:47 kernel: [BLOCKED - OUTBOUND] IN= OUT=ppp0 SRC=192.168.2.1 DST=23.95.186.183 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=TCP SPT=8443 DPT=48308 SEQ=173238269 ACK=1950839580 WINDOW=65340 R
May 9 10:39:05 kernel: [BLOCKED - OUTBOUND] IN= OUT=ppp0 SRC=192.168.2.1 DST=23.95.186.183 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=TCP SPT=8443 DPT=43518 SEQ=1558177459 ACK=1360031105 WINDOW=65340
May 9 10:39:07 kernel: [BLOCKED - OUTBOUND] IN= OUT=ppp0 SRC=192.168.2.1 DST=23.95.186.183 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=TCP SPT=8443 DPT=43518 SEQ=1558177459 ACK=1360031105 WINDOW=65340
Code:
10 Most Recent Blocks From 79.110.62.71;
May 9 03:05:09 kernel: [BLOCKED - INBOUND] IN=ppp0 OUT= MAC= SRC=79.110.62.71 DST=x.x.x.x LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=14238 PROTO=TCP SPT=56656 DPT=8443 SEQ=2722656114 ACK=0 WINDOW=1024 RES
May 9 04:27:19 kernel: [BLOCKED - OUTBOUND] IN= OUT=ppp0 SRC=192.168.2.1 DST=79.110.62.71 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=TCP SPT=8443 DPT=41449 SEQ=2514349906 ACK=858156911 WINDOW=65340 RE
May 9 04:27:20 kernel: [BLOCKED - OUTBOUND] IN= OUT=ppp0 SRC=192.168.2.1 DST=79.110.62.71 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=TCP SPT=8443 DPT=41449 SEQ=2514349906 ACK=858156911 WINDOW=65340 RE
May 9 05:42:38 kernel: [BLOCKED - INBOUND] IN=ppp0 OUT= MAC= SRC=79.110.62.71 DST=x.x.x.x LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=30068 PROTO=TCP SPT=45935 DPT=8443 SEQ=1545743768 ACK=0 WINDOW=1024 RES
May 9 07:03:40 kernel: [BLOCKED - OUTBOUND] IN= OUT=ppp0 SRC=192.168.2.1 DST=79.110.62.71 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=TCP SPT=8443 DPT=50954 SEQ=2356673267 ACK=2950742863 WINDOW=65340 R
May 9 07:03:41 kernel: [BLOCKED - OUTBOUND] IN= OUT=ppp0 SRC=192.168.2.1 DST=79.110.62.71 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=TCP SPT=8443 DPT=50954 SEQ=2356673267 ACK=2950742863 WINDOW=65340 R
May 9 08:20:24 kernel: [BLOCKED - INBOUND] IN=ppp0 OUT= MAC= SRC=79.110.62.71 DST=x.x.x.x LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=41978 PROTO=TCP SPT=55531 DPT=8443 SEQ=1331624726 ACK=0 WINDOW=1024 RES
May 9 09:46:58 kernel: [BLOCKED - OUTBOUND] IN= OUT=ppp0 SRC=192.168.2.1 DST=79.110.62.71 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=TCP SPT=8443 DPT=40663 SEQ=3534287188 ACK=3066922797 WINDOW=65340 R
May 9 09:46:59 kernel: [BLOCKED - OUTBOUND] IN= OUT=ppp0 SRC=192.168.2.1 DST=79.110.62.71 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=TCP SPT=8443 DPT=40663 SEQ=3534287188 ACK=3066922797 WINDOW=65340 R
May 9 11:02:32 kernel: [BLOCKED - INBOUND] IN=ppp0 OUT= MAC= SRC=79.110.62.71 DST=x.x.x.x LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=28062 PROTO=TCP SPT=45225 DPT=8443 SEQ=3766170994 ACK=0 WINDOW=1024 RES
How can I read this? It is router trying to make those connection or do they come from the LAN but the device is unidentified for some reason?
How can I further diagnose what's going on with those outbound connections? Like, how/where are they starting.
I'm using an AXE16000 with Merlin.
Thanks for your help.
Last edited: