Reply
oliversl
Posts: 26
Registered: ‎10-04-2007
Accepted Solution

VPN attack detected in VPN Log?

Hi,

I'm seeing this king of messages in the VPN Log:

 

Mar 4 15:55:10 2010     VPN Log    [Tunnel Negotiation Info] >>> Initiator Send Main Mode 1st packet

Mar 4 15:55:10 2010     VPN Log    [Tunnel Negotiation Info] >>> Initiator Send Main Mode 1st packet

Mar 4 15:55:10 2010     VPN Log    [Tunnel Negotiation Info] >>> Initiator Send Main Mode 1st packet

Mar 4 15:55:10 2010     VPN Log    [Tunnel Negotiation Info] >>> Initiator Send Main Mode 1st packet

Mar 4 15:55:10 2010     VPN Log    [Tunnel Negotiation Info] >>> Initiator Send Main Mode 1st packet

Mar 4 15:55:10 2010     VPN Log    [Tunnel Negotiation Info] >>> Initiator Send Main Mode 1st packet

Mar 4 15:55:10 2010     VPN Log    [Tunnel Negotiation Info] >>> Initiator Send Main Mode 1st packet

Mar 4 15:55:10 2010     VPN Log    [Tunnel Negotiation Info] >>> Initiator Send Main Mode 1st packet

Mar 4 15:55:10 2010     VPN Log    [Tunnel Negotiation Info] >>> Initiator Send Main Mode 1st packet

Mar 4 15:55:10 2010     VPN Log    [Tunnel Negotiation Info] >>> Initiator Send Main Mode 1st packet

Mar 4 15:55:10 2010     VPN Log    [Tunnel Negotiation Info] >>> Initiator Send Main Mode 1st packet

 

 

Those messages flooded the log page and have the same hour:minute:second

 

Is this some kind of attack or DoS?

 

 I have a Linksys RV082, firmware 2.0.0.19-tm

 

Many thanks

Oliver

http://tinymailto.com/oliversl --> My e-mail after a captcha
Dan Meyer
Posts: 162
Registered: ‎12-03-2009

Re: VPN attack detected in VPN Log?

This is quite interesting; every log entry has the same date and time, down to the second. Is there some way to find out what IP address this is coming from?
-- Dan Meyer
http://www.linkedin.com/in/danielrmeyer
oliversl
Posts: 26
Registered: ‎10-04-2007

Re: VPN attack detected in VPN Log?

Yes, they do have the same timestamp. Every few minutes or hours, a new round of attack flood the logs.

 

I added 2 rules in the firewall in order to catch the source IP. Will report back if it works. I block the port 500 and 60443 in the firewall rules, enabling logging.

 

 

Oliver 

http://tinymailto.com/oliversl --> My e-mail after a captcha
Expert
Expert
Posts: 12,649
Registered: ‎07-16-2006

Re: VPN attack detected in VPN Log?

Do you have any VPN tunnels configured on that router?
oliversl
Posts: 26
Registered: ‎10-04-2007

Re: VPN attack detected in VPN Log?

Yes, we have a VPN tunnel to another RV082 but it is disabled. Could this be the problem?

 

Thanks

Oliver 

http://tinymailto.com/oliversl --> My e-mail after a captcha
Expert
Expert
Posts: 12,649
Registered: ‎07-16-2006

Re: VPN attack detected in VPN Log?

Possible. Is the RV082 on the other side disabled as well?
oliversl
Posts: 26
Registered: ‎10-04-2007

Re: VPN attack detected in VPN Log?

Oh no, the other side was enabled, that was the cause. Many thanks!
http://tinymailto.com/oliversl --> My e-mail after a captcha