Hi,
I've been occasionally losing internet connectivity. The ADSL connection seems itself to be OK (per my ADSL modem D-LINK, DSL-504T, interface), however either a router (
www.clarkconnect.com, which terminates ppp connection), or ADSL modem (in bridge mode) reboot seems to clear things.
"snort" seems to be restarting in the mix of things and I was hoping someone could take a look at my logs below and see if they could spot anything? Logs are below. (REPEATING BITS REMOVED TO LOWER SIZE OF LOG)
Note, there are two points in the morning logs marked below. One when I restarted modem to fix issue, and 2nd time I restarted ClarkConnect router to correct issue.
ROUTER LOG
================================================================================
Oct 12 08:32:41 home dhclient: DHCPREQUEST on eth0 to 10.1.1.1 port 67
Oct 12 08:32:41 home dnsmasq[3379]: DHCPREQUEST(lo) 10.1.1.2 00:07:e3:cc:eb:12
Oct 12 08:32:41 home dnsmasq[3379]: DHCPNAK(lo) 10.1.1.2 00:07:e3:cc:eb:12 address not available
Oct 12 08:32:48 home dhclient: DHCPREQUEST on eth0 to 10.1.1.1 port 67
Oct 12 08:32:48 home dnsmasq[3379]: DHCPREQUEST(lo) 10.1.1.2 00:07:e3:cc:eb:12
Oct 12 08:32:48 home dnsmasq[3379]: DHCPNAK(lo) 10.1.1.2 00:07:e3:cc:eb:12 address not available
<<cut repeating bits to reduce size>
Oct 12 08:54:34 home dhclient: DHCPREQUEST on eth0 to 10.1.1.1 port 67
Oct 12 08:54:34 home dnsmasq[3379]: DHCPREQUEST(lo) 10.1.1.2 00:07:e3:cc:eb:12
Oct 12 08:54:34 home dnsmasq[3379]: DHCPNAK(lo) 10.1.1.2 00:07:e3:cc:eb:12 address not available
Oct 12 08:57:20 home dhclient: DHCPREQUEST on eth0 to 255.255.255.255 port 67
Oct 12 08:57:20 home dhclient: DHCPACK from 10.1.1.1
Oct 12 08:57:20 home dhclient: bound to 10.1.1.2 -- renewal in 1472 seconds.
Oct 12 09:21:52 home dhclient: DHCPREQUEST on eth0 to 10.1.1.1 port 67
Oct 12 09:21:52 home dnsmasq[3379]: DHCPREQUEST(lo) 10.1.1.2 00:07:e3:cc:eb:12
Oct 12 09:21:52 home dnsmasq[3379]: DHCPNAK(lo) 10.1.1.2 00:07:e3:cc:eb:12 address not available
<<cut repeating bits to reduce size>
Oct 12 09:48:00 home dhclient: DHCPREQUEST on eth0 to 10.1.1.1 port 67
Oct 12 09:48:00 home dnsmasq[3379]: DHCPREQUEST(lo) 10.1.1.2 00:07:e3:cc:eb:12
Oct 12 09:48:00 home dnsmasq[3379]: DHCPNAK(lo) 10.1.1.2 00:07:e3:cc:eb:12 address not available
Oct 12 09:51:13 home dhclient: DHCPREQUEST on eth0 to 255.255.255.255 port 67
Oct 12 09:51:13 home dhclient: DHCPACK from 10.1.1.1
Oct 12 09:51:13 home dhclient: bound to 10.1.1.2 -- renewal in 1414 seconds.
Oct 12 10:01:19 home dnsmasq[3379]: DHCPDISCOVER(eth1) 00:12:5a:b9:1d:14
Oct 12 10:01:19 home dnsmasq[3379]: DHCPOFFER(eth1) 10.1.1.111 00:12:5a:b9:1d:14
Oct 12 10:01:19 home dnsmasq[3379]: DHCPREQUEST(eth1) 10.1.1.111 00:12:5a:b9:1d:14
Oct 12 10:01:19 home dnsmasq[3379]: DHCPACK(eth1) 10.1.1.111 00:12:5a:b9:1d:14
<<cut repeating bits to reduce size>
Oct 12 10:18:04 home dhclient: DHCPREQUEST on eth0 to 10.1.1.1 port 67
Oct 12 10:18:04 home dnsmasq[3379]: DHCPREQUEST(lo) 10.1.1.2 00:07:e3:cc:eb:12
Oct 12 10:18:04 home dnsmasq[3379]: DHCPNAK(lo) 10.1.1.2 00:07:e3:cc:eb:12 address not available
Oct 12 10:18:25 home pppd[1842]: No response to 5 echo-requests
Oct 12 10:18:25 home pppd[1842]: Serial link appears to be disconnected.
Oct 12 10:18:25 home pppd[1842]: Connect time 186.0 minutes.
Oct 12 10:18:25 home pppd[1842]: Sent 12656857 bytes, received 325184364 bytes.
Oct 12 10:18:25 home snort[3454]: pcap_loop: recvfrom: Network is down
Oct 12 10:18:25 home snort[3454]: Final Flow Statistics
Oct 12 10:18:25 home snort[3454]: Frag3 statistics:
Oct 12 10:18:25 home snort[3454]: Total Fragments: 0
Oct 12 10:18:25 home snort[3454]: Frags Reassembled: 0
Oct 12 10:18:25 home snort[3454]: Discards: 0
Oct 12 10:18:25 home snort[3454]: Memory Faults: 0
Oct 12 10:18:25 home snort[3454]: Timeouts: 0
Oct 12 10:18:25 home snort[3454]: Overlaps: 0
Oct 12 10:18:25 home snort[3454]: Anomalies: 0
Oct 12 10:18:25 home snort[3454]: Alerts: 0
Oct 12 10:18:25 home snort[3454]: FragTrackers Added: 0
Oct 12 10:18:25 home snort[3454]: FragTrackers Dumped: 0
Oct 12 10:18:25 home snort[3454]: FragTrackers Auto Freed: 0
Oct 12 10:18:25 home snort[3454]: Frag Nodes Inserted: 0
Oct 12 10:18:25 home snort[3454]: Frag Nodes Deleted: 0
Oct 12 10:18:25 home snort[3454]: ===============================================================================
Oct 12 10:18:25 home snort[3454]: INFO => [Alert_FWsam](FWsamCheckOut) Disconnecting from host 127.0.0.1.
Oct 12 10:18:25 home snort[3454]: Snort exiting
Oct 12 10:18:25 home kernel: device ppp0 left promiscuous mode
Oct 12 10:18:25 home kernel: audit(1223770705.685:5): dev=ppp0 prom=0 old_prom=256 auid=4294967295
Oct 12 10:18:25 home NET: /etc/sysconfig/network-scripts/ifdown-post : updated /etc/resolv.conf
Oct 12 10:18:27 home dnsmasq[3379]: reading /etc/resolv.conf
Oct 12 10:18:27 home dnsmasq[3379]: ignoring nameserver 10.1.1.1 - local interface
Oct 12 10:18:28 home adsl-stop: Killing pppd
Oct 12 10:18:28 home pppd[1842]: Terminating on signal 15
Oct 12 10:18:28 home adsl-stop: Killing adsl-connect
Oct 12 10:18:31 home pppd[1842]: Connection terminated.
Oct 12 10:18:31 home pppd[1842]: Modem hangup
Oct 12 10:18:33 home pppd[1842]: Terminating on signal 15
Oct 12 10:18:33 home pppd[1842]: Exit.
Oct 12 10:18:33 home pppoe[1856]: read (asyncReadFromPPP): Session 366: Input/output error
Oct 12 10:18:33 home pppoe[1856]: Sent PADT
Oct 12 10:18:35 home dhclient: DHCPREQUEST on eth0 to 10.1.1.1 port 67
Oct 12 10:18:35 home dnsmasq[3379]: DHCPREQUEST(lo) 10.1.1.2 00:07:e3:cc:eb:12
Oct 12 10:18:35 home dnsmasq[3379]: DHCPNAK(lo) 10.1.1.2 00:07:e3:cc:eb:12 address not available
Oct 12 10:18:35 home pppd[16525]: pppd 2.4.3 started by root, uid 0
Oct 12 10:18:36 home pppd[16525]: Using interface ppp0
Oct 12 10:18:36 home pppd[16525]: Connect: ppp0 <--> /dev/pts/0
Oct 12 10:18:36 home pppoe[16526]: PPP session is 337
Oct 12 10:18:38 home pppd[16525]: PAP authentication succeeded
Oct 12 10:18:38 home pppd[16525]: local IP address 123.233.121.32
Oct 12 10:18:38 home pppd[16525]: remote IP address 10.20.20.210
Oct 12 10:18:38 home pppd[16525]: primary DNS address 203.12.160.35
Oct 12 10:18:38 home pppd[16525]: secondary DNS address 203.12.160.36
Oct 12 10:18:38 home NET: /etc/sysconfig/network-scripts/ifup-post : updated /etc/resolv.conf
Oct 12 10:18:39 home firewall: succeeded
Oct 12 10:18:40 home dnsmasq[3379]: reading /etc/resolv.conf
Oct 12 10:18:40 home dnsmasq[3379]: using nameserver 203.12.160.36#53
Oct 12 10:18:40 home dnsmasq[3379]: using nameserver 203.12.160.35#53
Oct 12 10:18:55 home firewall: succeeded
Oct 12 10:19:06 home firewall: succeeded
Oct 12 10:19:06 home snort: snort shutdown failed
Oct 12 10:19:07 home kernel: device ppp0 entered promiscuous mode
Oct 12 10:19:07 home kernel: audit(1223770747.015:6): dev=ppp0 prom=256 old_prom=0 auid=4294967295
Oct 12 10:19:07 home snort[17399]: Initializing daemon mode
Oct 12 10:19:07 home snort[17400]: PID path stat checked out ok, PID path set to /var/run/
Oct 12 10:19:07 home snort[17400]: Writing PID "17400" to file "/var/run//snort_ppp0.pid"
Oct 12 10:19:07 home snort[17400]: Parsing Rules file /etc/snort.conf
Oct 12 10:19:07 home snort[17400]: ,-----------[Flow Config]----------------------
Oct 12 10:19:07 home snort[17400]: | Stats Interval: 0
Oct 12 10:19:07 home snort[17400]: | Hash Method: 2
Oct 12 10:19:07 home snort[17400]: | Memcap: 10485760
Oct 12 10:19:07 home snort[17400]: | Rows : 4099
Oct 12 10:19:07 home snort[17400]: | Overhead Bytes: 16400(%0.16)
Oct 12 10:19:07 home snort: snort startup succeeded
Oct 12 10:19:07 home snort[17400]: `----------------------------------------------
Oct 12 10:19:07 home snort[17400]: Frag3 global config:
Oct 12 10:19:07 home snort[17400]: Max frags: 65536
Oct 12 10:19:07 home snort[17400]: Fragment memory cap: 4194304 bytes
Oct 12 10:19:07 home snort[17400]: Frag3 engine config:
Oct 12 10:19:07 home snort[17400]: Target-based policy: FIRST
Oct 12 10:19:07 home snort[17400]: Fragment timeout: 60 seconds
Oct 12 10:19:07 home snort[17400]: Fragment min_ttl: 1
Oct 12 10:19:07 home snort[17400]: Fragment ttl_limit: 5
Oct 12 10:19:07 home snort[17400]: Fragment Problems: 1
Oct 12 10:19:07 home snort[17400]: Bound Addresses: 0.0.0.0/0.0.0.0
Oct 12 10:19:07 home snort[17400]: Stream4 config:
Oct 12 10:19:07 home snort[17400]: Stateful inspection: ACTIVE
Oct 12 10:19:07 home snort[17400]: Session statistics: INACTIVE
Oct 12 10:19:07 home snort[17400]: Session timeout: 30 seconds
Oct 12 10:19:07 home snort[17400]: Session memory cap: 8388608 bytes
Oct 12 10:19:07 home snort[17400]: Session count max: 8192 sessions
Oct 12 10:19:07 home snort[17400]: Session cleanup count: 5
Oct 12 10:19:07 home snort[17400]: State alerts: INACTIVE
Oct 12 10:19:07 home snort[17400]: Evasion alerts: INACTIVE
Oct 12 10:19:07 home snort[17400]: Scan alerts: INACTIVE
Oct 12 10:19:07 home snort[17400]: Log Flushed Streams: INACTIVE
Oct 12 10:19:07 home snort[17400]: MinTTL: 1
Oct 12 10:19:07 home snort[17400]: TTL Limit: 5
Oct 12 10:19:07 home snort[17400]: Async Link: 0
Oct 12 10:19:07 home snort[17400]: State Protection: 0
Oct 12 10:19:07 home snort[17400]: Self preservation threshold: 50
Oct 12 10:19:07 home snort[17400]: Self preservation period: 90
Oct 12 10:19:07 home snort[17400]: Suspend threshold: 200
Oct 12 10:19:07 home snort[17400]: Suspend period: 30
Oct 12 10:19:07 home snort[17400]: Enforce TCP State: INACTIVE
Oct 12 10:19:07 home snort[17400]: Midstream Drop Alerts: INACTIVE
Oct 12 10:19:07 home snort[17400]: Server Data Inspection Limit: -1
Oct 12 10:19:07 home snort[17400]: WARNING /etc/snort.conf(373) => flush_behavior set in config file, using old static flushpoints (0)
Oct 12 10:19:07 home snort[17400]: Stream4_reassemble config:
Oct 12 10:19:07 home snort[17400]: Server reassembly: INACTIVE
Oct 12 10:19:07 home snort[17400]: Client reassembly: ACTIVE
Oct 12 10:19:07 home snort[17400]: Reassembler alerts: ACTIVE
Oct 12 10:19:07 home snort[17400]: Zero out flushed packets: INACTIVE
Oct 12 10:19:07 home snort[17400]: Flush stream on alert: INACTIVE
Oct 12 10:19:07 home snort[17400]: flush_data_diff_size: 500
Oct 12 10:19:07 home snort[17400]: Reassembler Packet Preferance : Favor Old
Oct 12 10:19:07 home snort[17400]: Packet Sequence Overlap Limit: -1
Oct 12 10:19:07 home snort[17400]: Flush behavior: Small (<255 bytes)
Oct 12 10:19:07 home snort[17400]: Ports: 21 23 25 42 53 80 110 111 135 136 137 139 143 445 513 1433 1521 3306
Oct 12 10:19:07 home snort[17400]: Emergency Ports: 21 23 25 42 53 80 110 111 135 136 137 139 143 445 513 1433 1521 3306
Oct 12 10:19:07 home snort[17400]: rpc_decode arguments:
Oct 12 10:19:07 home snort[17400]: Ports to decode RPC on: 111 32771
Oct 12 10:19:07 home snort[17400]: alert_fragments: INACTIVE
Oct 12 10:19:07 home snort[17400]: alert_large_fragments: ACTIVE
Oct 12 10:19:07 home snort[17400]: alert_incomplete: ACTIVE
Oct 12 10:19:07 home snort[17400]: alert_multiple_requests: ACTIVE
Oct 12 10:19:07 home snort[17400]: telnet_decode arguments:
Oct 12 10:19:07 home snort[17400]: Ports to decode telnet on: 21 23 25 119
Oct 12 10:19:07 home snort[17400]: Portscan Detection Config: