Community discussions

MikroTik App
 
ranjan
newbie
Topic Author
Posts: 31
Joined: Tue Nov 08, 2011 5:50 am

Help understanding Mikrotik LOG

Tue Dec 06, 2011 6:59 am

Dear All,
Today when I saw log of mikrotik then I found that there was some activity from firewall at night timing which actually worried me because we don't work at night.
So please help me understand the log what exactly is the meaning for no.1 and no.2 as shown in attached pic.
Thanks in advance.
You do not have the required permissions to view the files attached to this post.
 
User avatar
dasiu
Trainer
Trainer
Posts: 231
Joined: Fri Jan 30, 2009 11:41 am
Location: Reading, UK
Contact:

Re: Help understanding Mikrotik LOG

Tue Dec 06, 2011 9:35 am

1. a TCP SYN packet, initiating a TCP connection to port 22 (SSH) of your router. Someone (maybe a bot) was trying to SSH on the MikroTik
2. Every DHCP lease has its time. It is specified in "lease-time" parameter of the server. Usually - 3 days. If a DHCP client doesn't refresh the lease for the time - the lease is deassigned. That happened in the logs :).
 
ranjan
newbie
Topic Author
Posts: 31
Joined: Tue Nov 08, 2011 5:50 am

Re: Help understanding Mikrotik LOG

Tue Dec 06, 2011 9:43 am

1. a TCP SYN packet, initiating a TCP connection to port 22 (SSH) of your router. Someone (maybe a bot) was trying to SSH on the MikroTik
2. Every DHCP lease has its time. It is specified in "lease-time" parameter of the server. Usually - 3 days. If a DHCP client doesn't refresh the lease for the time - the lease is deassigned. That happened in the logs :).
Hi dasiu,
Thanks for explaining this.
someone is trying to ssh my router, so is that bot came in my network? How to block such intrusions which is coming through ssh?
Should I disable ssh from my router?
Please help me.
 
fewi
Forum Guru
Forum Guru
Posts: 7717
Joined: Tue Aug 11, 2009 3:19 am

Re: Help understanding Mikrotik LOG

Tue Dec 06, 2011 2:53 pm

Do you use SSH to access your router? If not best practice would be to disable the service.
 
ranjan
newbie
Topic Author
Posts: 31
Joined: Tue Nov 08, 2011 5:50 am

Re: Help understanding Mikrotik LOG

Wed Dec 07, 2011 6:21 am

Do you use SSH to access your router? If not best practice would be to disable the service.
Thanks fewi.
One more query I have related to upgradation of OS to v5.9, currently my winbox shows my version as v5.6.
After upgrade if anything goes wrong and I want to rollback to v5.6 with all previous configuration then how can I do that?
I have taken backup (Files>Backup).
Can u please tell me step by step process for taking MT RB450G router to its previous version (v5.6) and making it to working condition?
Thanks in advance.
 
Feklar
Forum Guru
Forum Guru
Posts: 1724
Joined: Tue Dec 01, 2009 11:46 pm

Re: Help understanding Mikrotik LOG

Wed Dec 07, 2011 5:02 pm

Search is your friend, that and the manual available at the wiki.
http://wiki.mikrotik.com/wiki/Manual:Ro ... owngrading

Configuration does not change from version to version, just syntax sometimes. Though having a backup of the router is never a bad idea.
 
ranjan
newbie
Topic Author
Posts: 31
Joined: Tue Nov 08, 2011 5:50 am

Re: Help understanding Mikrotik LOG

Fri Dec 09, 2011 6:44 am

Do you use SSH to access your router? If not best practice would be to disable the service.
Hello,
I have disabled my ssh on mikrotik but still I can that firewall info is showing that someone is trying to login.
Now what should I do?
Screen shot is attached.
Thanks in advance.
You do not have the required permissions to view the files attached to this post.
 
fewi
Forum Guru
Forum Guru
Posts: 7717
Joined: Tue Aug 11, 2009 3:19 am

Help understanding Mikrotik LOG

Fri Dec 09, 2011 2:03 pm

Nothing. What else is there to do? There's nothing listening on the port anymore, and you can't stop the packet from arriving on your router port (unless you control the other end of the connection as well).

Someone is trying a key on the door to your house. You changed the door so there's no longer a lock at all, but he keeps trying a key. Unless you control the street and can keep him from touching the door at all there's not much else you can do, but there is also little point in worrying about someone using a key if there's no actual lock to put the key in.
 
ranjan
newbie
Topic Author
Posts: 31
Joined: Tue Nov 08, 2011 5:50 am

Re: Help understanding Mikrotik LOG

Sat Dec 10, 2011 4:31 am

Nothing. What else is there to do? There's nothing listening on the port anymore, and you can't stop the packet from arriving on your router port (unless you control the other end of the connection as well).

Someone is trying a key on the door to your house. You changed the door so there's no longer a lock at all, but he keeps trying a key. Unless you control the street and can keep him from touching the door at all there's not much else you can do, but there is also little point in worrying about someone using a key if there's no actual lock to put the key in.
Thanks Fewi...

Who is online

Users browsing this forum: gigabyte091, qatar2022, vingjfg and 14 guests