cancel
Showing results for 
Search instead for 
Did you mean: 

Security Log TG582n

shure
Grafter
Posts: 509
Thanks: 1
Registered: 21-01-2013

Security Log TG582n

I'm getting the following in my router security logs.  Should I be worried?

Recorded Events

Time Message

Jan 21 14:48:38 FIREWALL replay check (1 of 4): Protocol: ICMP Src ip: 81.129.199.212 Dst ip: 87.114.48.21 Type: Destination Unreachable Code: Host Unreacheable

Jan 21 14:44:17 FIREWALL replay check (1 of 2): Protocol: ICMP Src ip: 81.156.50.135 Dst ip: 87.114.48.21 Type: Destination Unreachable Code: Host Unreacheable

Jan 21 14:38:25 FIREWALL replay check (1 of 4): Protocol: ICMP Src ip: 81.129.199.212 Dst ip: 87.114.48.21 Type: Destination Unreachable Code: Host Unreacheable

Jan 21 14:34:07 FIREWALL replay check (1 of 4): Protocol: ICMP Src ip: 81.156.50.135 Dst ip: 87.114.48.21 Type: Destination Unreachable Code: Host Unreacheable

Jan 21 14:21:42 FIREWALL replay check (1 of 4): Protocol: ICMP Src ip: 81.156.50.135 Dst ip: 87.114.48.21 Type: Destination Unreachable Code: Host Unreacheable

Jan 21 14:10:54 FIREWALL replay check (1 of 4): Protocol: ICMP Src ip: 86.136.182.73 Dst ip: 87.114.48.21 Type: Destination Unreachable Code: Host Unreacheable

Jan 21 14:00:42 FIREWALL replay check (1 of 4): Protocol: ICMP Src ip: 86.136.182.73 Dst ip: 87.114.48.21 Type: Destination Unreachable Code: Host Unreacheable

Jan 21 13:50:32 FIREWALL replay check (1 of 1): Protocol: ICMP Src ip: 86.136.182.73 Dst ip: 87.114.48.21 Type: Destination Unreachable Code: Host Unreacheable

Jan 21 13:41:24 FIREWALL replay check (1 of 5): Protocol: ICMP Src ip: 81.129.199.212 Dst ip: 87.114.48.21 Type: Destination Unreachable Code: Host Unreacheable

Jan 21 13:40:21 FIREWALL replay check (1 of 2): Protocol: ICMP Src ip: 86.136.182.73 Dst ip: 87.114.48.21 Type: Destination Unreachable Code: Host Unreacheable

Jan 21 13:30:21 FIREWALL replay check (1 of 4): Protocol: ICMP Src ip: 81.156.50.135 Dst ip: 87.114.48.21 Type: Destination Unreachable Code: Host Unreacheable

Jan 21 13:17:38 FIREWALL replay check (1 of 5): Protocol: ICMP Src ip: 81.156.50.135 Dst ip: 87.114.48.21 Type: Destination Unreachable Code: Host Unreacheable

Jan 21 12:45:12 FIREWALL replay check (1 of Cool: Protocol: ICMP Src ip: 81.129.199.212 Dst ip: 87.114.48.21 Type: Destination Unreachable Code: Host Unreacheable

Jan 21 12:37:39 FIREWALL icmp check (1 of 6): Protocol: ICMP Src ip: 66.207.80.7 Dst ip: 87.114.48.21 Type: Destination Unreachable Code: Port Unreacheable

Jan 21 12:34:51 FIREWALL replay check (1 of Cool: Protocol: ICMP Src ip: 81.129.199.212 Dst ip: 87.114.48.21 Type: Destination Unreachable Code: Host Unreacheable

Jan 21 12:23:59 FIREWALL replay check (1 of 6): Protocol: ICMP Src ip: 86.181.65.209 Dst ip: 87.114.48.21 Type: Destination Unreachable Code: Host Unreacheable

Jan 21 12:15:08 FIREWALL replay check (1 of 11): Protocol: ICMP Src ip: 81.129.199.212 Dst ip: 87.114.48.21 Type: Destination Unreachable Code: Host Unreacheable
5 REPLIES
Superuser
Superuser
Posts: 9,577
Thanks: 955
Fixes: 54
Registered: 06-04-2007

Re: Security Log TG582n

These types of message are normal and show that the router firewall is doing its job - preventing unsolicited access to computers on your LAN from the internet.
Nothing to be concerned about unless they become very frequent.
David
shure
Grafter
Posts: 509
Thanks: 1
Registered: 21-01-2013

Re: Security Log TG582n

many thanks spraxyt
quelquod
Aspiring Pro
Posts: 526
Thanks: 57
Registered: 31-07-2007

Re: Security Log TG582n

As mentioned above it's just the router denying access to fishing expeditions. By the way if you've been doing any P2P such as sharing torrents this broadcasts your IP and can result in people just having a ping to see if you are unprotected.
Democracy - 3 wolves and a lamb voting about what to have for lunch!
shure
Grafter
Posts: 509
Thanks: 1
Registered: 21-01-2013

Re: Security Log TG582n

@quelquod
thanks for the tip.  I'm not but need to check the offspring aren't doing it behind my back Grin
Community Veteran
Posts: 5,109
Thanks: 465
Fixes: 17
Registered: 10-06-2010

Re: Security Log TG582n

Or it could just be the router blocking legitimate traffic because it arrived too late, or too many arrived all at the same time.
The log message itself is fairly unhelpful, because it just gives some of the details of the packet, but doesn't actually say why it failed the check.