Ich habe hier einen 1790VA, FW 10.50.0530RU4, bei dem ich das Verhalten der automatischen Firewall/Intruder Detection im Kontext des Line-Pollings nicht verstehe. Mit dem Polling überwache ich eine Kabel-und eine DSL-Verbindung, die jeweils über eine FritzBox bereitgestellt wird.
Bei der Kabel-Verbinndung sah es im Polling so aus als ob es keine ICMP Replys gibt, in der Folge wird die Verbindung alle 60s getrennt und versucht neu aufzubauen. Im Trace:
Code: Alles auswählen
[Line-Polling] 2022/05/10 10:55:10,312 Devicetime: 2022/05/10 10:55:11,574 IPv4 Line Polling [failed] on interface GS-CABLE: Sent ping to 1.1.1.1
[Line-Polling] 2022/05/10 10:55:10,312 Devicetime: 2022/05/10 10:55:11,574 IPv4 Line Polling [failed] on interface GS-CABLE: Sent ping to 1.0.0.1
[Line-Polling] 2022/05/10 10:55:11,312 Devicetime: 2022/05/10 10:55:12,574 IPv4 Line Polling [failed] on interface GS-CABLE: No ping reply received. Remaining retries: 17
[Line-Polling] 2022/05/10 10:55:11,312 Devicetime: 2022/05/10 10:55:12,574 IPv4 Line Polling [failed] on interface GS-CABLE: Sent ping to 1.1.1.1
[Line-Polling] 2022/05/10 10:55:11,312 Devicetime: 2022/05/10 10:55:12,574 IPv4 Line Polling [failed] on interface GS-CABLE: Sent ping to 1.0.0.1
[Line-Polling] 2022/05/10 10:55:11,504 Devicetime: 2022/05/10 10:55:12,756 IPv4 Line Polling [forced] on interface GS-VDSL: Ping reply received during last poll period. Next check in 20s
[Line-Polling] 2022/05/10 10:55:11,504 Devicetime: 2022/05/10 10:55:12,756 IPv4 Line Polling [forced] on interface GS-VDSL: Sent ping to 8.8.8.8
[Line-Polling] 2022/05/10 10:55:11,504 Devicetime: 2022/05/10 10:55:12,756 IPv4 Line Polling [forced] on interface GS-VDSL: Sent ping to 8.8.4.4
Code: Alles auswählen
26 7.070240 109.90.xx.xx 1.1.1.1 ICMP 98 Echo (ping) request id=0x578e, seq=4/1024, ttl=64 (reply in 28)
27 7.070254 109.90.xx.xx 1.0.0.1 ICMP 98 Echo (ping) request id=0x578e, seq=4/1024, ttl=64 (reply in 29)
28 7.079686 1.1.1.1 109.90.xx.xx ICMP 98 Echo (ping) reply id=0x578e, seq=4/1024, ttl=56 (request in 26)
29 7.079699 1.0.0.1 109.90.xx.xx ICMP 98 Echo (ping) reply id=0x578e, seq=4/1024, ttl=56 (request in 27)

Code: Alles auswählen
[Firewall] 2022/05/10 11:21:50,725 Devicetime: 2022/05/10 11:21:52,063
Packet matched rule intruder detection
DstIP: 109.90.xx.xx, SrcIP: 1.1.1.1, Len: 84, DSCP: CS0/BE (0x00), ECT: 0, CE: 0
Prot.: ICMP (1), echo reply, id: 0x5912, seq: 0x0001
Filter info: packet received from invalid interface GS-CABLE
send SNMP trap
packet dropped
VG,
Matschek