Nie jesteś zalogowany.
Jeśli nie posiadasz konta, zarejestruj je już teraz! Pozwoli Ci ono w pełni korzystać z naszego serwisu. Spamerom dziękujemy!
Prosimy o pomoc dla małej Julki — przekaż 1% podatku na Fundacji Dzieciom zdazyć z Pomocą.
Więcej informacji na dug.net.pl/pomagamy/.
Obecnie logowałem do maszyny wirtualnej na Centos - ip 192.168.0.9, a chcę jeszcze na NAS'a Synology - ip 192.168.0.3. Na serwerze, źródłowym w rsyslog.conf dodałem jeszcze jeden wpis mam:
########## *.* @@192.168.0.9 *.* @@192.168.0.3
Na NAS odblokowałem port TCP 514 ustawiłem lokalizację dla logów. Sprawdziłem z hosta źródłowego czy port jest otwarty:
telnet 192.168.0.3 514 Trying 192.168.0.3... Connected to 192.168.0.3. Escape character is '^]'.
W ustawieniach nas włączyłem odbieranie logów z innych urządzeń (ustawienia formatu IETF - czy dobrze czy BSD ma być?). TCPdumpem sprawdzam czy host wysyłający logi generuje ruch do 192.168.0.3:
10:00:01.575595 IP 192.168.0.3.514 > 192.168.0.7.47778: Flags [R], seq 3171870648, win 0, length 0 10:00:01.983152 IP 192.168.0.7.47778 > 192.168.0.3.514: Flags [F.], seq 0, ack 1, win 46, options [nop,nop,TS val 113620877 ecr 973272643], length 0 10:00:01.983356 IP 192.168.0.3.514 > 192.168.0.7.47778: Flags [R], seq 3171870648, win 0, length 0 10:00:02.640620 ARP, Request who-has 192.168.0.3 (ff:ff:ff:ff:ff:ff) tell 192.168.0.1, length 46 10:00:02.799149 IP 192.168.0.7.47778 > 192.168.0.3.514: Flags [F.], seq 0, ack 1, win 46, options [nop,nop,TS val 113621081 ecr 973272643], length 0 10:00:02.799372 IP 192.168.0.3.514 > 192.168.0.7.47778: Flags [R], seq 3171870648, win 0, length 0 10:00:04.431230 IP 192.168.0.7.47778 > 192.168.0.3.514: Flags [F.], seq 0, ack 1, win 46, options [nop,nop,TS val 113621489 ecr 973272643], length 0 10:00:04.431578 IP 192.168.0.3.514 > 192.168.0.7.47778: Flags [R], seq 3171870648, win 0, length 0 10:00:06.389669 ARP, Request who-has 192.168.0.7 tell 192.168.0.3, length 46 10:00:06.389680 ARP, Reply 192.168.0.7 is-at e2:e6:1a:a2:2a:cf, length 28 10:00:07.695216 IP 192.168.0.7.47778 > 192.168.0.3.514: Flags [F.], seq 0, ack 1, win 46, options [nop,nop,TS val 113622305 ecr 973272643], length 0 10:00:07.695483 IP 192.168.0.3.514 > 192.168.0.7.47778: Flags [R], seq 3171870648, win 0, length 0 10:00:14.223150 IP 192.168.0.7.47778 > 192.168.0.3.514: Flags [F.], seq 0, ack 1, win 46, options [nop,nop,TS val 113623937 ecr 973272643], length 0 10:00:14.223690 IP 192.168.0.3.514 > 192.168.0.7.47778: Flags [R], seq 3171870648, win 0, length 0 10:00:27.279155 IP 192.168.0.7.47778 > 192.168.0.3.514: Flags [F.], seq 0, ack 1, win 46, options [nop,nop,TS val 113627201 ecr 973272643], length 0 10:00:27.279767 IP 192.168.0.3.514 > 192.168.0.7.47778: Flags [R], seq 3171870648, win 0, length 0 10:00:53.391222 IP 192.168.0.7.47778 > 192.168.0.3.514: Flags [F.], seq 0, ack 1, win 46, options [nop,nop,TS val 113633729 ecr 973272643], lengt
Nie widać próby nawiązania połączenia src 192.168.0.7 - dst 192.168.0.3, tylko wymuszenie zresetowania połączenia wysłane z 192.168.0.3 - NAS serwer logowań.
Offline
Prostuję nawiązywanie połączenia również jest widoczne:
08:52:58.558807 IP 192.168.0.8.51592 > 192.168.0.3.514: Flags [s], seq 1731138 132, win 14600, options [mss 1460,sackOK,TS val 55159387 ecr 0,nop,wscale 2], length 0 08:52:58.559290 IP 192.168.0.8.51592 > 192.168.0.3.514: Flags [.], ack 2001515 423, win 3650, options [nop,nop,TS val 55159387 ecr 1315550018], length 0 08:52:58.559414 IP 192.168.0.8.51592 > 192.168.0.3.514: Flags [P.], seq 0:87, ack 1, win 3650, options [nop,nop,TS val 55159387 ecr 1315550018], length 87 08:52:58.647594 IP 192.168.0.8.51592 > 192.168.0.3.514: Flags [.], ack 2, win 3650, options [nop,nop,TS val 55159409 ecr 1315550106], length 0
Offline
Time (s) | Query |
---|---|
0.00018 | SET CHARSET latin2 |
0.00009 | SET NAMES latin2 |
0.00204 | SELECT u.*, g.*, o.logged FROM punbb_users AS u INNER JOIN punbb_groups AS g ON u.group_id=g.g_id LEFT JOIN punbb_online AS o ON o.ident='18.219.18.238' WHERE u.id=1 |
0.00135 | UPDATE punbb_online SET logged=1732747151 WHERE ident='18.219.18.238' |
0.00108 | SELECT * FROM punbb_online WHERE logged<1732746851 |
0.00141 | DELETE FROM punbb_online WHERE ident='18.119.167.189' |
0.00090 | DELETE FROM punbb_online WHERE ident='18.216.145.37' |
0.00111 | SELECT topic_id FROM punbb_posts WHERE id=300600 |
0.00112 | SELECT id FROM punbb_posts WHERE topic_id=28513 ORDER BY posted |
0.00084 | SELECT t.subject, t.closed, t.num_replies, t.sticky, f.id AS forum_id, f.forum_name, f.moderators, fp.post_replies, 0 FROM punbb_topics AS t INNER JOIN punbb_forums AS f ON f.id=t.forum_id LEFT JOIN punbb_forum_perms AS fp ON (fp.forum_id=f.id AND fp.group_id=3) WHERE (fp.read_forum IS NULL OR fp.read_forum=1) AND t.id=28513 AND t.moved_to IS NULL |
0.00009 | SELECT search_for, replace_with FROM punbb_censoring |
0.00191 | SELECT u.email, u.title, u.url, u.location, u.use_avatar, u.signature, u.email_setting, u.num_posts, u.registered, u.admin_note, p.id, p.poster AS username, p.poster_id, p.poster_ip, p.poster_email, p.message, p.hide_smilies, p.posted, p.edited, p.edited_by, g.g_id, g.g_user_title, o.user_id AS is_online FROM punbb_posts AS p INNER JOIN punbb_users AS u ON u.id=p.poster_id INNER JOIN punbb_groups AS g ON g.g_id=u.group_id LEFT JOIN punbb_online AS o ON (o.user_id=u.id AND o.user_id!=1 AND o.idle=0) WHERE p.topic_id=28513 ORDER BY p.id LIMIT 0,25 |
0.00085 | UPDATE punbb_topics SET num_views=num_views+1 WHERE id=28513 |
Total query time: 0.01297 s |