I was checking out a D834g looking at the stats as the rain forecast sometimes makes the phone hissier. Quick look in the log and you see the usual blocked hack attempts though the entries aren't as detailed as my own router.
10 hours later went back in and stats only had about 10% change. However, looking at the log again and scroll to end and - yikes!! The last entry showwed my login but the 8 lines before that were like this:
date src-a.b.c.d,port type-tcp dstn-192.168.x.x,123
date src-a1.b1.c1.d1,port type-tcp dstn-192.168.x.x,123
plus 6 more
the abcd WAN addresses were mostly different, 2 the same had a different port number.
The relevant point of worry is that ALL the prior log entries show the dstn as the router's front-facing IP,port.
Why is there a block on a seemingly straight attempt to the LAN's private address range which is supposedly unseeable from the WAN?
And the port 123 is the NTP time protocol, so is there some scam around now that uses this?
If, and maybe if, you look on these entries as showing what the firewall has _actually_ blocked then no worry, but the previous question still applies.
Notes about the setup.
The D834g had its wi-fi OFF. ALL WAN ports blocked, NO remote, upnp, igmp, dmz.
The laptop I used both times booted from a CD and this does NOT want anything more than the DHCP/DNS for the card.
About that last sentence; I worked out from the log times that the first of those 8 scam entries was within about 10sec of when the laptop would be setting the card up. BUT, going back up the log to the earlier login there was nothing similar and it doesn't happen on my own system.



Print Thread
deleted