Please post the output of;
Code:sh /jffs/scripts/firewall debug info
I got it working by doing a reinstall. Now the malware and country lists are loaded as expected.
Thanks.
Please post the output of;
Code:sh /jffs/scripts/firewall debug info
rt-3100 merlin 384.7 diversion 4.03
the cpu was running under 5%
installed skynet with 1gb swap file
the cpu is now running at 50% avg
even in the middle of the night with
nobody active. did i install it wrong?
if i find skynet interferes too much with my
normal online activity, how do i remove it?
is it bound too much to diversion,
so i'll have to uninstall both and then
reinstall diversion alone?
also, i see a lot of discussion about adding
a range of whitelists, presumably these are
known retail referral hosts that if blocked
may interfere too much with browsing.
so where can i find these popular whitelist domain ranges?
i see people on this thread discussing them, but no actual
faq or reference to their common "approved" source.
also, once diversion+skynet is running correctly,
do i still need to keep aiprotection running from asus?
or like merlin compliments asus stock,
so does skynet compliments aiprotection.
Getting this now?
Oct 24 12:28:31 Skynet: [%] Startup Initiated... ( skynetloc=/tmp/mnt/sda/skynet )
Oct 24 12:28:51 Skynet: [#] 178 IPs (+0) -- 0 Ranges Banned (+0) || 0 Inbound -- 0 Outbound Connections Blocked! [start] [20s]
Oct 25 02:00:08 Skynet: [#] 129685 IPs (+0) -- 4880 Ranges Banned (+0) || 4923 Inbound -- 103 Outbound Connections Blocked! [save] [8s]
Oct 25 02:26:20 Skynet: [#] 128794 IPs (-891) -- 4702 Ranges Banned (-178) || 4965 Inbound -- 103 Outbound Connections Blocked! [banmalware] [80s]
Oct 25 03:00:08 Skynet: [#] 128794 IPs (+0) -- 4702 Ranges Banned (+0) || 5023 Inbound -- 103 Outbound
.........
Oct 25 10:26:20 Skynet: [#] 130552 IPs (+1758) -- 4702 Ranges Banned (+0) || 5846 Inbound -- 103 Outbound Connections Blocked! [banmalware] [42s]
I always lose IPs during nighly update and have to manually update banmalware to get the numbers back up.
That’s a funny looking Skynet . Please try with Skynet, that way I know exactly what’s going on based on the output.
Thanks Adamm, Been spending a bit of time on the analysis of the logs.
I have blocked countries ru kr kp ir cn.
My stats show tons of outgoing blocks to loads of pool.ntp.org IP's. I assume these are from blocked countries and I can whitelist this domain ? :
12x https://otx.alienvault.com/indicator/ip/203.217.204.135 - [asia.pool.ntp.org pool.ntp.org]
11x https://otx.alienvault.com/indicator/ip/211.233.84.186 - [pool.ntp.org]
11x https://otx.alienvault.com/indicator/ip/211.233.40.78 - [pool.ntp.org]
7x https://otx.alienvault.com/indicator/ip/185.105.186.198 - [pool.ntp.org]
5x https://otx.alienvault.com/indicator/ip/195.78.244.50 - [pool.ntp.org]
2x https://otx.alienvault.com/indicator/ip/91.198.10.4 - [pool.ntp.org]
2x https://otx.alienvault.com/indicator/ip/85.21.78.23 - [pool.ntp.org]
2x https://otx.alienvault.com/indicator/ip/80.240.216.155 - [pool.ntp.org]
2x https://otx.alienvault.com/indicator/ip/79.142.192.4 - [pool.ntp.org]
2x https://otx.alienvault.com/indicator/ip/195.210.189.106 - [pool.ntp.org]
2x https://otx.alienvault.com/indicator/ip/193.27.209.211 - [pool.ntp.org]
2x https://otx.alienvault.com/indicator/ip/193.27.209.20 - [pool.ntp.org]
2x https://otx.alienvault.com/indicator/ip/185.103.110.248 - [pool.ntp.org]
2x https://otx.alienvault.com/indicator/ip/144.217.181.221 - [pool.ntp.org]
1x https://otx.alienvault.com/indicator/ip/94.247.111.10 - [pool.ntp.org]
1x https://otx.alienvault.com/indicator/ip/91.218.89.74 - [pool.ntp.org]
1x https://otx.alienvault.com/indicator/ip/89.221.207.113 - [pool.ntp.org]
1x https://otx.alienvault.com/indicator/ip/89.175.20.7 - [pool.ntp.org]
1x https://otx.alienvault.com/indicator/ip/85.93.216.115 - [pool.ntp.org]
1x http://otx.alienvault.com/indicator/ip/85.21.78.91 - [pool.ntp.org]
1x https://otx.alienvault.com/indicator/ip/79.142.192.130 - [pool.ntp.org]
1x https://otx.alienvault.com/indicator/ip/78.140.251.2 - [pool.ntp.org]
1x https://otx.alienvault.com/indicator/ip/46.173.6.142 - [pool.ntp.org]
1x https://otx.alienvault.com/indicator/ip/195.78.244.34 - [pool.ntp.org]
1x https://otx.alienvault.com/indicator/ip/193.27.208.100 - [pool.ntp.org]
Oct 27 19:07:59 kernel: [BLOCKED - OUTBOUND] IN= OUT=eth0 SRC=213.112.x.x DST=1.1.1.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=ICMP TYPE=8 CODE=0 ID=27230 SEQ=0
Oct 27 19:13:35 kernel: [BLOCKED - OUTBOUND] IN= OUT=eth0 SRC=213.112.x.x DST=1.1.1.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=ICMP TYPE=8 CODE=0 ID=40544 SEQ=0
Oct 27 19:13:45 kernel: [BLOCKED - OUTBOUND] IN= OUT=eth0 SRC=213.112.x.x DST=1.1.1.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=ICMP TYPE=8 CODE=0 ID=44384 SEQ=0
Oct 27 19:13:55 kernel: [BLOCKED - OUTBOUND] IN= OUT=eth0 SRC=213.112.x.x DST=1.1.1.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=ICMP TYPE=8 CODE=0 ID=53088 SEQ=0
Oct 27 19:14:05 kernel: [BLOCKED - OUTBOUND] IN= OUT=eth0 SRC=213.112.x.x DST=1.1.1.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=ICMP TYPE=8 CODE=0 ID=62304 SEQ=0
Getting alot of after update to v6.5.3
I have not added cloudflare to any list..Why have you got cloudflare dns blocked?
I have not added cloudflare to any list..
Happend after update
And i Dont use 1.1.1.1 for any devices or router
Halp - BestApp.exe or BestWebsite.com Is Being Blocked;
Don't worry, tracking down false positive bans was at the core of design. Generally speaking you can follow these steps to find (and whitelist) anything incorrectly on your Blacklist!
1.) Enable Debug Mode
Code:sh /jffs/scripts/firewall settings debugmode enable
2.) Open the blocked application/website and use the command;
Code:sh /jffs/scripts/firewall debug watch
Now look for a flood of [BLOCKED - OUTBOUND] coming from the same IP. This most likely will be the IP you are looking for if its being spammed in large numbers.
3.) Copy the IP following "DST=" it should look something like this;
Code:DST=175.115.37.52
4.) Double check the IP is not actually something that should be banned, use a search tool like alienvault. If its related to a domain additional "Associated Domain" information should be printed beneath the log.
Code:https://otx.alienvault.com/indicator/ip/175.115.37.52/
5.) Great we have confirmed we found the IP of the blocked website/application we are looking for, lets whitelist it!
Code:sh /jffs/scripts/firewall whitelist ip 175.115.37.52
I had the same block occur after updating. I resolved by white listing 1.1.1.1 and 1.0.0.1.I suggest looking at the ban reason for the entry and removing it.
https://pastebin.com/raw/iFqeTvkF
Oct 28 12:08:23 kernel: Set Skynet-Blacklist is full, maxelem 500000 reached
Oct 28 12:08:51 Skynet: [#] 500000 IPs (+369267) -- 0 Ranges Banned (-4708) || 1983 Inbound -- 12 Outbound Connections Blocked! [banmalware] [126s]
That’s crazy. By right, firehol lvl 1-3 is more than enough and unauthorised entry would have been blocked by router own firewall.I just wanted to share my custom filter list:
I addedCode:https://pastebin.com/raw/iFqeTvkF
https://hosts.ubuntu101.co.za/ips.list from https://github.com/mitchellkrogza/Ultimate.Hosts.Blacklist, now skynet says it reached it's limit with 500.000 blocked ips. :-D
Code:Oct 28 12:08:23 kernel: Set Skynet-Blacklist is full, maxelem 500000 reached Oct 28 12:08:51 Skynet: [#] 500000 IPs (+369267) -- 0 Ranges Banned (-4708) || 1983 Inbound -- 12 Outbound Connections Blocked! [banmalware] [126s]
@Adamm Can you cancel the limit? And why are the ranges gone?
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!