That’s a 10 MB (output) file LOL.
So I was just passing through the WebGUI And noticed they seem to be inboud TO my public IP. But the source MAC does not match anything on my network (still verifying) and the inbound NEWNOTSYN have numerous Source IPs.
Restated… Inbound NewNotSYN:
Numerous Source IPs (varying subnets and GeoIP ranges)
Single Source MAC
Destination is my Public IP, not anything NAT behind the Firewall.
From 14:27 to 14:31 today there are only 211 Lines.
Of those, 198 are “IN=red0”
Of those, there are 27 unique IP’s with a single MAC:
[root@skynet ~]# grep -e "IN=red0" temp1.txt |sort -t'=' -k4|cut -d ' ' -f 5-11|sort -u
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=104.16.109.79
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=157.245.185.115
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=162.125.19.131
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=162.159.130.233
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=162.159.136.234
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=172.217.165.142
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=172.217.9.238
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=191.101.50.190
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=198.22.253.113
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=23.10.88.237
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=23.223.156.43
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=3.213.182.132
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=3.226.165.42
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=3.231.74.94
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=34.200.63.6
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=34.233.202.213
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=34.238.26.171
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=35.153.172.172
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=35.172.64.65
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=35.186.224.44
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=40.126.28.13
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=52.167.253.237
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=52.230.222.68
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=52.242.211.89
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=52.32.34.32
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=52.84.130.63
skynet kernel: DROP_NEWNOTSYN IN=red0 OUT= MAC=00:1c:c0:43:47:2f:00:01:5c:8b:9e:46:08:00 SRC=52.84.53.61
[root@skynet ~]# grep -e "IN=red0" temp1.txt |sort -t'=' -k4|cut -d ' ' -f 5-11|sort -u|grep -c .
27
104.16.109.79
157.245.185.115
162.125.19.131
162.159.130.233
162.159.136.234
172.217.165.142
172.217.9.238
191.101.50.190
198.22.253.113
23.10.88.237
23.223.156.43
3.213.182.132
3.226.165.42
3.231.74.94
34.200.63.6
34.233.202.213
34.238.26.171
35.153.172.172
35.172.64.65
35.186.224.44
40.126.28.13
52.167.253.237
52.230.222.68
52.242.211.89
52.32.34.32
52.84.130.63
52.84.53.61