Пропадает нет, пинги идут нормально, потом превышен интервал ожидания, потом опять нормально.[more=Лог]
System Log
Date/Time Facility Severity Message
Jan 3 22:46:39 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=78.111.148.31 DST=87.117.12.115 LEN=48 TOS=0x00 PREC=0x00 TTL=116 ID=17179 DF PROTO=TCP SPT=52699 DPT=14961 WINDOW=8192 RES=0x00 SYN URGP=0
Jan 3 22:49:46 user warn dnsprobe[565]: dns query failed
Jan 3 22:49:48 user warn dnsprobe[565]: dns query failed
Jan 3 22:49:50 user warn dnsprobe[565]: dns query failed
Jan 3 22:49:50 user notice dnsprobe[565]: Primary DNS server Is Down... Switching To Secondary DNS server
Jan 3 22:51:28 daemon crit pppd[269]: Clear IP addresses. Connection DOWN.
Jan 3 22:51:28 daemon crit pppd[269]: Clear IP addresses. PPP connection DOWN.
Jan 3 22:51:38 daemon notice pppd[269]: PPP: Start to connect ...
Jan 3 22:51:46 daemon crit pppd[269]: PPP LCP UP.
Jan 3 22:51:46 daemon crit pppd[269]: Received valid IP address from server. Connection UP.
Jan 3 22:52:00 daemon crit pppd[269]: Clear IP addresses. Connection DOWN.
Jan 3 22:52:00 daemon crit pppd[269]: Clear IP addresses. PPP connection DOWN.
Jan 3 22:52:00 daemon crit pppd[269]: PPP LCP UP.
Jan 3 22:52:06 daemon notice pppd[269]: PPP: Start to connect ...
Jan 3 22:52:13 daemon crit pppd[269]: PPP LCP UP.
Jan 3 22:52:14 daemon crit pppd[269]: Received valid IP address from server. Connection UP.
Jan 3 22:52:14 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=93.178.111.144 DST=109.165.30.116 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=16707 DF PROTO=TCP SPT=2274 DPT=22430 WINDOW=65535 RES=0x00 SYN URGP=0
Jan 3 22:52:15 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=109.165.110.17 DST=109.165.30.116 LEN=48 TOS=0x00 PREC=0x00 TTL=124 ID=29969 DF PROTO=TCP SPT=14073 DPT=22430 WINDOW=65535 RES=0x00 SYN URGP=0
Jan 3 22:52:17 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=77.232.15.254 DST=109.165.30.116 LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=15634 DF PROTO=TCP SPT=36984 DPT=22430 WINDOW=8192 RES=0x00 SYN URGP=0
Jan 3 22:52:17 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=89.250.7.26 DST=109.165.30.116 LEN=48 TOS=0x00 PREC=0x00 TTL=118 ID=1559 DF PROTO=TCP SPT=56826 DPT=22430 WINDOW=65535 RES=0x00 SYN URGP=0
Jan 3 22:52:17 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=94.50.162.48 DST=109.165.30.116 LEN=48 TOS=0x00 PREC=0x00 TTL=117 ID=13846 DF PROTO=TCP SPT=65124 DPT=22430 WINDOW=8192 RES=0x00 SYN URGP=0
[/more]
Интересуют расшифровки конца лога, в начале то что днс падает-только сегодня появилось, дело не в этом.
System Log
Date/Time Facility Severity Message
Jan 3 22:46:39 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=78.111.148.31 DST=87.117.12.115 LEN=48 TOS=0x00 PREC=0x00 TTL=116 ID=17179 DF PROTO=TCP SPT=52699 DPT=14961 WINDOW=8192 RES=0x00 SYN URGP=0
Jan 3 22:49:46 user warn dnsprobe[565]: dns query failed
Jan 3 22:49:48 user warn dnsprobe[565]: dns query failed
Jan 3 22:49:50 user warn dnsprobe[565]: dns query failed
Jan 3 22:49:50 user notice dnsprobe[565]: Primary DNS server Is Down... Switching To Secondary DNS server
Jan 3 22:51:28 daemon crit pppd[269]: Clear IP addresses. Connection DOWN.
Jan 3 22:51:28 daemon crit pppd[269]: Clear IP addresses. PPP connection DOWN.
Jan 3 22:51:38 daemon notice pppd[269]: PPP: Start to connect ...
Jan 3 22:51:46 daemon crit pppd[269]: PPP LCP UP.
Jan 3 22:51:46 daemon crit pppd[269]: Received valid IP address from server. Connection UP.
Jan 3 22:52:00 daemon crit pppd[269]: Clear IP addresses. Connection DOWN.
Jan 3 22:52:00 daemon crit pppd[269]: Clear IP addresses. PPP connection DOWN.
Jan 3 22:52:00 daemon crit pppd[269]: PPP LCP UP.
Jan 3 22:52:06 daemon notice pppd[269]: PPP: Start to connect ...
Jan 3 22:52:13 daemon crit pppd[269]: PPP LCP UP.
Jan 3 22:52:14 daemon crit pppd[269]: Received valid IP address from server. Connection UP.
Jan 3 22:52:14 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=93.178.111.144 DST=109.165.30.116 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=16707 DF PROTO=TCP SPT=2274 DPT=22430 WINDOW=65535 RES=0x00 SYN URGP=0
Jan 3 22:52:15 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=109.165.110.17 DST=109.165.30.116 LEN=48 TOS=0x00 PREC=0x00 TTL=124 ID=29969 DF PROTO=TCP SPT=14073 DPT=22430 WINDOW=65535 RES=0x00 SYN URGP=0
Jan 3 22:52:17 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=77.232.15.254 DST=109.165.30.116 LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=15634 DF PROTO=TCP SPT=36984 DPT=22430 WINDOW=8192 RES=0x00 SYN URGP=0
Jan 3 22:52:17 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=89.250.7.26 DST=109.165.30.116 LEN=48 TOS=0x00 PREC=0x00 TTL=118 ID=1559 DF PROTO=TCP SPT=56826 DPT=22430 WINDOW=65535 RES=0x00 SYN URGP=0
Jan 3 22:52:17 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=94.50.162.48 DST=109.165.30.116 LEN=48 TOS=0x00 PREC=0x00 TTL=117 ID=13846 DF PROTO=TCP SPT=65124 DPT=22430 WINDOW=8192 RES=0x00 SYN URGP=0
[/more]
Интересуют расшифровки конца лога, в начале то что днс падает-только сегодня появилось, дело не в этом.