03-04-2010 02:41 PM
Hi,
I'm seeing this king of messages in the VPN Log:
Mar 4 15:55:10 2010 VPN Log [Tunnel Negotiation Info] >>> Initiator Send Main Mode 1st packet
Mar 4 15:55:10 2010 VPN Log [Tunnel Negotiation Info] >>> Initiator Send Main Mode 1st packet
Mar 4 15:55:10 2010 VPN Log [Tunnel Negotiation Info] >>> Initiator Send Main Mode 1st packet
Mar 4 15:55:10 2010 VPN Log [Tunnel Negotiation Info] >>> Initiator Send Main Mode 1st packet
Mar 4 15:55:10 2010 VPN Log [Tunnel Negotiation Info] >>> Initiator Send Main Mode 1st packet
Mar 4 15:55:10 2010 VPN Log [Tunnel Negotiation Info] >>> Initiator Send Main Mode 1st packet
Mar 4 15:55:10 2010 VPN Log [Tunnel Negotiation Info] >>> Initiator Send Main Mode 1st packet
Mar 4 15:55:10 2010 VPN Log [Tunnel Negotiation Info] >>> Initiator Send Main Mode 1st packet
Mar 4 15:55:10 2010 VPN Log [Tunnel Negotiation Info] >>> Initiator Send Main Mode 1st packet
Mar 4 15:55:10 2010 VPN Log [Tunnel Negotiation Info] >>> Initiator Send Main Mode 1st packet
Mar 4 15:55:10 2010 VPN Log [Tunnel Negotiation Info] >>> Initiator Send Main Mode 1st packet
Those messages flooded the log page and have the same hour:minute:second
Is this some kind of attack or DoS?
I have a Linksys RV082, firmware 2.0.0.19-tm
Many thanks
Oliver
Solved! Go to Solution.
03-05-2010 06:55 AM
03-05-2010 07:04 AM
Yes, they do have the same timestamp. Every few minutes or hours, a new round of attack flood the logs.
I added 2 rules in the firewall in order to catch the source IP. Will report back if it works. I block the port 500 and 60443 in the firewall rules, enabling logging.
Oliver
03-05-2010 09:13 AM
03-05-2010 10:21 AM
Yes, we have a VPN tunnel to another RV082 but it is disabled. Could this be the problem?
Thanks
Oliver
03-05-2010 11:43 AM
03-06-2010 06:36 AM