Ok since this thread is here, I will re-use it.
I found today that an IP from Microsoft got banned by skynet. No idea why, but it did. I unbanned it and the app worked again. As I was watching the firewall syslog (suggested from skynet post), I saw a string of outbound port 53 UDP blocks. I looked up the IP on alienvault and it shows up as Korean Internet Security Agency. Of course that is freaking me out now.
The source was a Windows Domain Controller server that was apparently trying to connect on port 53 UDP to that IP. I cannot figure out why that was happening. According to skynet, it just started happening on 4-28-2021. It was happening while I was watching for about 20 attempts and then it stopped. The IP is: 210.101.60.1.
Here is an example of my skynet logs:
May 3 18:29:50 kernel: [BLOCKED - OUTBOUND] IN=br0 OUT= MAC=10:c3:7b:40:34:08:00:15:5d:63:c9:01:08:00 SRC=192.X.X.X DST=210.101.60.1 LEN=60 TOS=0x00 PREC=0x00 TTL=128 ID=22041 PROTO=UDP SPT=49595 DPT=53 LEN=40
Any thoughts?
got any IoT devices on the network? you may want to look into enabling DNS filter on your router which can block/redirect these lookups to undesired DNS serversOk since this thread is here, I will re-use it.
I found today that an IP from Microsoft got banned by skynet. No idea why, but it did. I unbanned it and the app worked again. As I was watching the firewall syslog (suggested from skynet post), I saw a string of outbound port 53 UDP blocks. I looked up the IP on alienvault and it shows up as Korean Internet Security Agency. Of course that is freaking me out now.
The source was a Windows Domain Controller server that was apparently trying to connect on port 53 UDP to that IP. I cannot figure out why that was happening. According to skynet, it just started happening on 4-28-2021. It was happening while I was watching for about 20 attempts and then it stopped. The IP is: 210.101.60.1.
Here is an example of my skynet logs:
May 3 18:29:50 kernel: [BLOCKED - OUTBOUND] IN=br0 OUT= MAC=10:c3:7b:40:34:08:00:15:5d:63:c9:01:08:00 SRC=192.X.X.X DST=210.101.60.1 LEN=60 TOS=0x00 PREC=0x00 TTL=128 ID=22041 PROTO=UDP SPT=49595 DPT=53 LEN=40
Any thoughts?
Any thoughts?
When I look at the skynet logs, I am surprised at how many blocks there are.
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!