Killing the Mikrotik Cloud?
Posted: Sun Nov 11, 2018 11:41 am
A few times now I see the Evil Google DNS trying to connect endless to my DNS port which is blocked to by a RAW rule. In this way I can fill my log files very fast by only that log entry repeating and repeating endlessly.
An other strange thing is that displayed log looks different in the sequence of the events;
In the logfile itself it is correctly sequenced:
These is the start of log.0.txt and log.4.txt and so in total 4000 lines of the same and I lost so the part of the log I ought to have.Nov/11/2018 08:29:06 firewall,info Drop RAW - Probe prerouting: in:pppoe-out1 out:(unknown 0), src-mac 54:1e:56:3c:68:62, proto UDP, 8.8.8.8:53->wan.wan.wan.wan:5678, len 80
Nov/11/2018 08:29:07 firewall,info Drop RAW - Probe prerouting: in:pppoe-out1 out:(unknown 0), src-mac 54:1e:56:3c:68:62, proto UDP, 8.8.8.8:53->wan.wan.wan.wan:5678, len 80
Nov/11/2018 08:29:08 firewall,info Drop RAW - Probe prerouting: in:pppoe-out1 out:(unknown 0), src-mac 54:1e:56:3c:68:62, proto UDP, 8.8.8.8:53->wan.wan.wan.wan:5678, len 80
Nov/11/2018 08:29:09 firewall,info Drop RAW - Probe prerouting: in:pppoe-out1 out:(unknown 0), src-mac 54:1e:56:3c:68:62, proto UDP, 8.8.8.8:53->wan.wan.wan.wan:5678, len 80
.
.
Nov/11/2018 09:36:17 firewall,info Drop RAW - Probe prerouting: in:pppoe-out1 out:(unknown 0), src-mac 54:1e:56:3c:68:62, proto UDP, 8.8.8.8:53->wan.wan.wan.wan:5678, len 80
Nov/11/2018 09:36:18 firewall,info Drop RAW - Probe prerouting: in:pppoe-out1 out:(unknown 0), src-mac 54:1e:56:3c:68:62, proto UDP, 8.8.8.8:53->wan.wan.wan.wan:5678, len 80
Nov/11/2018 09:36:19 firewall,info Drop RAW - Probe prerouting: in:pppoe-out1 out:(unknown 0), src-mac 54:1e:56:3c:68:62, proto UDP, 8.8.8.8:53->wan.wan.wan.wan:5678, len 80
Nov/11/2018 09:36:20 firewall,info Drop RAW - Probe prerouting: in:pppoe-out1 out:(unknown 0), src-mac 54:1e:56:3c:68:62, proto UDP, 8.8.8.8:53->wan.wan.wan.wan:5678, len 80
Nov/11/2018 09:36:21 firewall,info Drop RAW - Probe prerouting: in:pppoe-out1 out:(unknown 0), src-mac 54:1e:56:3c:68:62, proto UDP, 8.8.8.8:53->wan.wan.wan.wan:5678, len 80
An other strange thing is that displayed log looks different in the sequence of the events;
I see the show log a misplaced 09:34:05 timestamp between 10:02:22 and 10:04:22 of two minutes DNS request for the Cloud I don't use.Nov/11/2018 09:56:22 firewall,info icmp - related input: in:master-bridge out:(unknown 0), src-mac 40:8d:5c:b2:fa:ed, proto ICMP (type 3, code 3), 192.168.xxx.xxx->192.168.xxx.xxx, len 139
Nov/11/2018 09:56:22 firewall,info Drop RAW - Probe prerouting: in:pppoe-out1 out:(unknown 0), proto UDP, 8.8.8.8:53->wan.wan.wan.wan:5678, len 80
Nov/11/2018 09:58:22 firewall,info icmp - related input: in:master-bridge out:(unknown 0), src-mac 40:8d:5c:b2:fa:ed, proto ICMP (type 3, code 3), 192.168.xxx.xxx->192.168.xxx.xxx, len 139
Nov/11/2018 09:58:22 firewall,info Drop RAW - Probe prerouting: in:pppoe-out1 out:(unknown 0), proto UDP, 8.8.8.8:53->wan.wan.wan.wan:5678, len 80
Nov/11/2018 10:00:22 firewall,info icmp - related input: in:master-bridge out:(unknown 0), src-mac 40:8d:5c:b2:fa:ed, proto ICMP (type 3, code 3), 192.168.xxx.xxx->192.168.xxx.xxx, len 139
Nov/11/2018 10:00:22 firewall,info Drop RAW - Probe prerouting: in:pppoe-out1 out:(unknown 0), proto UDP, 8.8.8.8:53->wan.wan.wan.wan:5678, len 80
Nov/11/2018 10:02:22 firewall,info icmp - related input: in:master-bridge out:(unknown 0), src-mac 40:8d:5c:b2:fa:ed, proto ICMP (type 3, code 3), 192.168.xxx.xxx->192.168.xxx.xxx, len 139
Nov/11/2018 10:02:22 firewall,info Drop RAW - Probe prerouting: in:pppoe-out1 out:(unknown 0), proto UDP, 8.8.8.8:53->wan.wan.wan.wan:5678, len 80
Nov/11/2018 10:04:22 firewall,info icmp - related input: in:master-bridge out:(unknown 0), src-mac 40:8d:5c:b2:fa:ed, proto ICMP (type 3, code 3), 192.168.xxx.xxx->192.168.xxx.xxx, len 139
Nov/11/2018 10:04:22 firewall,info Drop RAW - Probe prerouting: in:pppoe-out1 out:(unknown 0), proto UDP, 8.8.8.8:53->wan.wan.wan.wan:5678, len 80
In the logfile itself it is correctly sequenced:
Nov/11/2018 09:30:03 firewall,info Drop RAW - Probe prerouting: in:pppoe-out1 out:(unknown 0), src-mac 54:1e:56:3c:68:62, proto UDP, 8.8.8.8:53->wan.wan.wan.wan:5678, len 80
Nov/11/2018 09:30:04 firewall,info Drop RAW - Probe prerouting: in:pppoe-out1 out:(unknown 0), src-mac 54:1e:56:3c:68:62, proto UDP, 8.8.8.8:53->wan.wan.wan.wan:5678, len 80
Nov/11/2018 09:30:05 firewall,info Drop RAW - Probe prerouting: in:pppoe-out1 out:(unknown 0), proto UDP, 8.8.8.8:53->wan.wan.wan.wan:5678, len 80
Nov/11/2018 09:32:05 firewall,info Drop RAW - Probe prerouting: in:pppoe-out1 out:(unknown 0), proto UDP, 8.8.8.8:53->wan.wan.wan.wan:5678, len 80
Nov/11/2018 09:34:05 firewall,info Drop RAW - Probe prerouting: in:pppoe-out1 out:(unknown 0), proto UDP, 8.8.8.8:53->wan.wan.wan.wan:5678, len 80
Nov/11/2018 09:36:05 firewall,info Drop RAW - Probe prerouting: in:pppoe-out1 out:(unknown 0), src-mac 54:1e:56:3c:68:62, proto UDP, 8.8.8.8:53->wan.wan.wan.wan:5678, len 80