marcjoerg
14.01.06, 18:54
Hi!
Ich dachte erst, ich brauche so viel Traffic pro Tag, aber nachdem ich mal einen Tag lang alle Client-PCs aus hatte, sah ich, dass der Linux-Server wohl so an die 70MB Traffic pro Tag verursacht. Ein Blick in die /var/log/message lieferte mir folgendes:
Jan 14 19:36:17 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.212.65.5, dev eth0
Jan 14 19:36:28 HSI-KBW-082-321-543-231 kernel: SFW2-INext-DROP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.34.50 DST=82.212.60.224 LEN=48 TOS=0x02 PREC=0x00 TTL=127 ID=22475 DF PROTO=TCP SPT=2197 DPT=139 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:36:31 HSI-KBW-082-321-543-231 kernel: SFW2-INext-DROP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.34.50 DST=82.212.60.224 LEN=48 TOS=0x02 PREC=0x00 TTL=127 ID=22874 DF PROTO=TCP SPT=2197 DPT=139 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:36:44 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.212.65.5, dev eth0
Jan 14 19:36:50 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.217.33.1, dev eth0
Jan 14 19:36:52 HSI-KBW-082-321-543-231 last message repeated 2 times
Jan 14 19:37:00 HSI-KBW-082-321-543-231 /usr/sbin/cron[7042]: (*system*) RELOAD (/etc/crontab)
Jan 14 19:37:15 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.212.65.5, dev eth0
Jan 14 19:37:25 HSI-KBW-082-321-543-231 last message repeated 2 times
Jan 14 19:37:32 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.217.33.1, dev eth0
Jan 14 19:37:34 HSI-KBW-082-321-543-231 last message repeated 2 times
Jan 14 19:37:55 HSI-KBW-082-321-543-231 kernel: SFW2-INext-DROP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.130.156 DST=82.212.60.224 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=16473 DF PROTO=TCP SPT=3639 DPT=139 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:37:58 HSI-KBW-082-321-543-231 kernel: SFW2-INext-DROP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.130.156 DST=82.212.60.224 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=17048 DF PROTO=TCP SPT=3639 DPT=139 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:37:59 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.212.65.5, dev eth0
Jan 14 19:38:00 HSI-KBW-082-321-543-231 /usr/sbin/cron[7042]: (*system*) RELOAD (/etc/crontab)
Jan 14 19:38:02 HSI-KBW-082-321-543-231 kernel: SFW2-INext-ACC-TCP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.130.156 DST=82.212.60.224 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=17890 DF PROTO=TCP SPT=4983 DPT=445 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:38:02 HSI-KBW-082-321-543-231 kernel: SFW2-INext-ACC-TCP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.130.156 DST=82.212.60.224 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=17909 DF PROTO=TCP SPT=1030 DPT=445 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:38:02 HSI-KBW-082-321-543-231 smbd[13444]: [2006/01/14 19:38:02, 0] lib/access.c:check_access(328)
Jan 14 19:38:02 HSI-KBW-082-321-543-231 smbd[13444]: Denied connection from (82.212.130.156)
Jan 14 19:38:02 HSI-KBW-082-321-543-231 kernel: SFW2-INext-DROP-DEFLT IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=221.5.251.234 DST=82.212.60.224 LEN=485 TOS=0x00 PREC=0x00 TTL=43 ID=0 DF PROTO=UDP SPT=38326 DPT=1026 LEN=465
Jan 14 19:38:05 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.217.33.1, dev eth0
Jan 14 19:38:08 HSI-KBW-082-321-543-231 last message repeated 2 times
Jan 14 19:38:38 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.212.65.5, dev eth0
Jan 14 19:39:08 HSI-KBW-082-321-543-231 kernel: SFW2-INext-ACC-TCP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.30.219 DST=82.212.60.224 LEN=64 TOS=0x02 PREC=0x00 TTL=120 ID=2756 DF PROTO=TCP SPT=2616 DPT=445 WINDOW=8576 RES=0x00 SYN URGP=0 OPT (02040218010303000101080A000000000000000001010402)
Jan 14 19:39:08 HSI-KBW-082-321-543-231 kernel: SFW2-INext-ACC-TCP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.30.219 DST=82.212.60.224 LEN=64 TOS=0x02 PREC=0x00 TTL=120 ID=2759 DF PROTO=TCP SPT=2617 DPT=445 WINDOW=8576 RES=0x00 SYN URGP=0 OPT (02040218010303000101080A000000000000000001010402)
Jan 14 19:39:08 HSI-KBW-082-321-543-231 smbd[13452]: [2006/01/14 19:39:08, 0] lib/access.c:check_access(328)
Jan 14 19:39:08 HSI-KBW-082-321-543-231 smbd[13452]: Denied connection from (82.212.30.219)
Jan 14 19:39:10 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.212.65.5, dev eth0
Jan 14 19:39:19 HSI-KBW-082-321-543-231 kernel: SFW2-INext-ACC-TCP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.130.156 DST=82.212.60.224 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=33576 DF PROTO=TCP SPT=3611 DPT=445 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:39:20 HSI-KBW-082-321-543-231 kernel: SFW2-INext-ACC-TCP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.130.156 DST=82.212.60.224 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=33662 DF PROTO=TCP SPT=3670 DPT=445 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:39:20 HSI-KBW-082-321-543-231 kernel: SFW2-INext-DROP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.130.156 DST=82.212.60.224 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=33668 DF PROTO=TCP SPT=3672 DPT=139 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:39:20 HSI-KBW-082-321-543-231 smbd[13455]: [2006/01/14 19:39:20, 0] lib/access.c:check_access(328)
Jan 14 19:39:20 HSI-KBW-082-321-543-231 smbd[13455]: Denied connection from (82.212.130.156)
Jan 14 19:39:21 HSI-KBW-082-321-543-231 kernel: SFW2-INext-DROP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.130.156 DST=82.212.60.224 LEN=48 TOS=0x08 PREC=0x00 TTL=111 ID=34018 DF PROTO=TCP SPT=3909 DPT=80 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:39:23 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.212.65.5, dev eth0
Jan 14 19:39:24 HSI-KBW-082-321-543-231 kernel: SFW2-INext-DROP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.130.156 DST=82.212.60.224 LEN=48 TOS=0x08 PREC=0x00 TTL=111 ID=34633 DF PROTO=TCP SPT=3909 DPT=80 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:39:30 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.217.33.1, dev eth0
Jan 14 19:39:31 HSI-KBW-082-321-543-231 kernel: SFW2-INext-DROP-DEFLT IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.130.156 DST=82.212.60.224 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=35807 DF PROTO=TCP SPT=1489 DPT=135 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:39:31 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.217.33.1, dev eth0
Jan 14 19:39:31 HSI-KBW-082-321-543-231 kernel: SFW2-INext-DROP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.130.156 DST=82.212.60.224 LEN=48 TOS=0x08 PREC=0x00 TTL=111 ID=35857 DF PROTO=TCP SPT=3909 DPT=80 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:39:33 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.212.65.5, dev eth0
Jan 14 19:39:33 HSI-KBW-082-321-543-231 kernel: SFW2-INext-DROP-DEFLT IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.130.156 DST=82.212.60.224 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=36389 DF PROTO=TCP SPT=1489 DPT=135 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:39:48 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.212.65.5, dev eth0
Jan 14 19:40:00 HSI-KBW-082-321-543-231 /USR/SBIN/CRON[13470]: (root) CMD (if [ -x /usr/bin/vnstat ] && [ `ls /var/lib/vnstat/ | wc -l` -ge 1 ]; then /usr/bin/vnstat -u; fi)
Jan 14 19:40:00 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.217.33.1, dev eth0
Jan 14 19:40:02 HSI-KBW-082-321-543-231 last message repeated 2 times
Jan 14 19:40:27 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.212.65.5, dev eth0
Jan 14 19:40:33 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.217.33.1, dev eth0
Jan 14 19:40:35 HSI-KBW-082-321-543-231 last message repeated 2 times
Jan 14 19:40:42 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.212.65.5, dev eth0
Jan 14 19:41:00 HSI-KBW-082-321-543-231 last message repeated 2 times
Jan 14 19:41:06 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.217.33.1, dev eth0
Jan 14 19:41:08 HSI-KBW-082-321-543-231 last message repeated 2 times
Kann da jemand was heraus finden? Ist das was schlimmes, oder ist 70MB Traffic pro Tag einfach normal?
Danke und Grüße
Marc
Ich dachte erst, ich brauche so viel Traffic pro Tag, aber nachdem ich mal einen Tag lang alle Client-PCs aus hatte, sah ich, dass der Linux-Server wohl so an die 70MB Traffic pro Tag verursacht. Ein Blick in die /var/log/message lieferte mir folgendes:
Jan 14 19:36:17 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.212.65.5, dev eth0
Jan 14 19:36:28 HSI-KBW-082-321-543-231 kernel: SFW2-INext-DROP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.34.50 DST=82.212.60.224 LEN=48 TOS=0x02 PREC=0x00 TTL=127 ID=22475 DF PROTO=TCP SPT=2197 DPT=139 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:36:31 HSI-KBW-082-321-543-231 kernel: SFW2-INext-DROP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.34.50 DST=82.212.60.224 LEN=48 TOS=0x02 PREC=0x00 TTL=127 ID=22874 DF PROTO=TCP SPT=2197 DPT=139 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:36:44 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.212.65.5, dev eth0
Jan 14 19:36:50 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.217.33.1, dev eth0
Jan 14 19:36:52 HSI-KBW-082-321-543-231 last message repeated 2 times
Jan 14 19:37:00 HSI-KBW-082-321-543-231 /usr/sbin/cron[7042]: (*system*) RELOAD (/etc/crontab)
Jan 14 19:37:15 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.212.65.5, dev eth0
Jan 14 19:37:25 HSI-KBW-082-321-543-231 last message repeated 2 times
Jan 14 19:37:32 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.217.33.1, dev eth0
Jan 14 19:37:34 HSI-KBW-082-321-543-231 last message repeated 2 times
Jan 14 19:37:55 HSI-KBW-082-321-543-231 kernel: SFW2-INext-DROP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.130.156 DST=82.212.60.224 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=16473 DF PROTO=TCP SPT=3639 DPT=139 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:37:58 HSI-KBW-082-321-543-231 kernel: SFW2-INext-DROP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.130.156 DST=82.212.60.224 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=17048 DF PROTO=TCP SPT=3639 DPT=139 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:37:59 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.212.65.5, dev eth0
Jan 14 19:38:00 HSI-KBW-082-321-543-231 /usr/sbin/cron[7042]: (*system*) RELOAD (/etc/crontab)
Jan 14 19:38:02 HSI-KBW-082-321-543-231 kernel: SFW2-INext-ACC-TCP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.130.156 DST=82.212.60.224 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=17890 DF PROTO=TCP SPT=4983 DPT=445 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:38:02 HSI-KBW-082-321-543-231 kernel: SFW2-INext-ACC-TCP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.130.156 DST=82.212.60.224 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=17909 DF PROTO=TCP SPT=1030 DPT=445 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:38:02 HSI-KBW-082-321-543-231 smbd[13444]: [2006/01/14 19:38:02, 0] lib/access.c:check_access(328)
Jan 14 19:38:02 HSI-KBW-082-321-543-231 smbd[13444]: Denied connection from (82.212.130.156)
Jan 14 19:38:02 HSI-KBW-082-321-543-231 kernel: SFW2-INext-DROP-DEFLT IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=221.5.251.234 DST=82.212.60.224 LEN=485 TOS=0x00 PREC=0x00 TTL=43 ID=0 DF PROTO=UDP SPT=38326 DPT=1026 LEN=465
Jan 14 19:38:05 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.217.33.1, dev eth0
Jan 14 19:38:08 HSI-KBW-082-321-543-231 last message repeated 2 times
Jan 14 19:38:38 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.212.65.5, dev eth0
Jan 14 19:39:08 HSI-KBW-082-321-543-231 kernel: SFW2-INext-ACC-TCP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.30.219 DST=82.212.60.224 LEN=64 TOS=0x02 PREC=0x00 TTL=120 ID=2756 DF PROTO=TCP SPT=2616 DPT=445 WINDOW=8576 RES=0x00 SYN URGP=0 OPT (02040218010303000101080A000000000000000001010402)
Jan 14 19:39:08 HSI-KBW-082-321-543-231 kernel: SFW2-INext-ACC-TCP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.30.219 DST=82.212.60.224 LEN=64 TOS=0x02 PREC=0x00 TTL=120 ID=2759 DF PROTO=TCP SPT=2617 DPT=445 WINDOW=8576 RES=0x00 SYN URGP=0 OPT (02040218010303000101080A000000000000000001010402)
Jan 14 19:39:08 HSI-KBW-082-321-543-231 smbd[13452]: [2006/01/14 19:39:08, 0] lib/access.c:check_access(328)
Jan 14 19:39:08 HSI-KBW-082-321-543-231 smbd[13452]: Denied connection from (82.212.30.219)
Jan 14 19:39:10 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.212.65.5, dev eth0
Jan 14 19:39:19 HSI-KBW-082-321-543-231 kernel: SFW2-INext-ACC-TCP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.130.156 DST=82.212.60.224 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=33576 DF PROTO=TCP SPT=3611 DPT=445 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:39:20 HSI-KBW-082-321-543-231 kernel: SFW2-INext-ACC-TCP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.130.156 DST=82.212.60.224 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=33662 DF PROTO=TCP SPT=3670 DPT=445 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:39:20 HSI-KBW-082-321-543-231 kernel: SFW2-INext-DROP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.130.156 DST=82.212.60.224 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=33668 DF PROTO=TCP SPT=3672 DPT=139 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:39:20 HSI-KBW-082-321-543-231 smbd[13455]: [2006/01/14 19:39:20, 0] lib/access.c:check_access(328)
Jan 14 19:39:20 HSI-KBW-082-321-543-231 smbd[13455]: Denied connection from (82.212.130.156)
Jan 14 19:39:21 HSI-KBW-082-321-543-231 kernel: SFW2-INext-DROP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.130.156 DST=82.212.60.224 LEN=48 TOS=0x08 PREC=0x00 TTL=111 ID=34018 DF PROTO=TCP SPT=3909 DPT=80 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:39:23 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.212.65.5, dev eth0
Jan 14 19:39:24 HSI-KBW-082-321-543-231 kernel: SFW2-INext-DROP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.130.156 DST=82.212.60.224 LEN=48 TOS=0x08 PREC=0x00 TTL=111 ID=34633 DF PROTO=TCP SPT=3909 DPT=80 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:39:30 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.217.33.1, dev eth0
Jan 14 19:39:31 HSI-KBW-082-321-543-231 kernel: SFW2-INext-DROP-DEFLT IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.130.156 DST=82.212.60.224 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=35807 DF PROTO=TCP SPT=1489 DPT=135 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:39:31 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.217.33.1, dev eth0
Jan 14 19:39:31 HSI-KBW-082-321-543-231 kernel: SFW2-INext-DROP IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.130.156 DST=82.212.60.224 LEN=48 TOS=0x08 PREC=0x00 TTL=111 ID=35857 DF PROTO=TCP SPT=3909 DPT=80 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:39:33 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.212.65.5, dev eth0
Jan 14 19:39:33 HSI-KBW-082-321-543-231 kernel: SFW2-INext-DROP-DEFLT IN=eth0 OUT= MAC=00:c0:26:28:41:07:00:50:57:01:21:69:08:00 SRC=82.212.130.156 DST=82.212.60.224 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=36389 DF PROTO=TCP SPT=1489 DPT=135 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405B401010402)
Jan 14 19:39:48 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.212.65.5, dev eth0
Jan 14 19:40:00 HSI-KBW-082-321-543-231 /USR/SBIN/CRON[13470]: (root) CMD (if [ -x /usr/bin/vnstat ] && [ `ls /var/lib/vnstat/ | wc -l` -ge 1 ]; then /usr/bin/vnstat -u; fi)
Jan 14 19:40:00 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.217.33.1, dev eth0
Jan 14 19:40:02 HSI-KBW-082-321-543-231 last message repeated 2 times
Jan 14 19:40:27 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.212.65.5, dev eth0
Jan 14 19:40:33 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.217.33.1, dev eth0
Jan 14 19:40:35 HSI-KBW-082-321-543-231 last message repeated 2 times
Jan 14 19:40:42 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.212.65.5, dev eth0
Jan 14 19:41:00 HSI-KBW-082-321-543-231 last message repeated 2 times
Jan 14 19:41:06 HSI-KBW-082-321-543-231 kernel: martian destination 0.0.0.0 from 82.217.33.1, dev eth0
Jan 14 19:41:08 HSI-KBW-082-321-543-231 last message repeated 2 times
Kann da jemand was heraus finden? Ist das was schlimmes, oder ist 70MB Traffic pro Tag einfach normal?
Danke und Grüße
Marc