Minoz Цитата: просто... Зато теперь у меня фсе "левые пакеты" блокируются одним последним правилом,
Ну ежели от замены строчки типа
Цитата: 2006/08/27, 22:49:30.890, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
на строчку с указанием номера правила становится легче на душе - пользуйте так
dariusii Цитата: Накидал аудит на все, что только мог.
- а в конфигурации вот енто самое правило для "не подпадающих под правила" лог отчеркнул? Просто траффик, не подпадающий под всевозможные правила, мягко говоря, [more=несколько больший]
Код: 2006/08/27, 22:55:48.730, GMT +0200, 2111, Device 1, Rule 77, Blocked incoming MAC packet, src=00-40-F4-11-BC-E4, dst=FF-FF-FF-FF-FF-FF
2006/08/27, 22:55:48.730, GMT +0200, 2111, Device 1, Rule 77, Blocked incoming MAC packet, src=00-40-F4-11-BC-E4, dst=FF-FF-FF-FF-FF-FF
2006/08/27, 22:55:52.570, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:55:54.440, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:55:54.440, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:55:55.760, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:55:57.900, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:55:59.820, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:55:59.820, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:56:06.250, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.11, dst=192.168.1.1
2006/08/27, 22:56:22.780, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:56:26.740, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:56:26.740, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:56:29.590, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:56:29.590, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:56:30.580, GMT +0200, 2128, Device 1, Blocked UDP packet from banned IP, src=192.168.1.33, dst=192.168.1.255, sport=138, dport=138
2006/08/27, 22:56:30.640, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:56:30.640, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:56:31.680, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:56:54.090, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:56:55.190, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:56:55.190, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:56:55.850, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:56:57.330, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:56:57.880, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:57:20.730, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:57:20.730, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:57:22.380, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:57:22.380, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:57:23.750, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:57:25.450, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:57:26.270, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:57:26.270, GMT +0200, 2018, Device 1, Blocked incoming ARP packet (no matching rule), src=192.168.1.1, dst=192.168.1.105
2006/08/27, 22:57:27.370, GMT +0200, 2128, Device 1, Blocked UDP packet from banned IP, src=192.168.1.15, dst=192.168.1.255, sport=137, dport=137