What's the Mongolian connection?
FIXED- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Help with my Plusnet services
- :
- My Router
- :
- Re: What's the Mongolian connection?
18-02-2020 1:17 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I see the following in my router log:
12:15:20, 18 Feb. (1826286.400000) PPPoE is down after 2016 minutes uptime [Waiting for Underlying Connection (WAN Ethernet 7 - Down)]
12:15:17, 18 Feb. (1826283.860000) PPP LCP Send Termination Request [User request]
12:14:58, 18 Feb. IN: BLOCK [16] Remote administration (TCP [122.201.19.99]:56199->[nn.nn.nn.nn]:8080 on ppp3)
(My IP address hidden)
According to geoip, 122.201.19.99 is in Mongolia! I also note we see the URL "https://dbtpnhdm.bt.mo" in logs quite often.
Who logs into my router to control it from Mongolia? I find it rather disconcerting, given the security implications of the Internet, and concern about Russia and China, between which Mongolia is sandwiched.
Fixed! Go to the fix.
18-02-2020 1:46 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Hey @kjpetrie,
Thanks for highlighting this. It's not uncommon to see IP addresses or web URLS in the router log for your router - the router is blocking these and essentially doing the job it's designed to do. If you have any concerns about the security of your connection, you can force the router to assign you another IP address by turning it off overnight, though I would stress that this won't prevent 3rd parties testing your connection - as previously mentioned, this is commonplace and the router is designed to prevent access to your connection - exactly as it has done so in the screenshot you've provided.
Thanks.
Re: What's the Mongolian connection?
18-02-2020 5:26 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Oh, I see. I was fooled by the next two lines into thinking the connection had succeeded and issued the request to disconnect and reset the WAN after doing whatever it did. I didn't notice that big "BLOCK" response rejecting the access attempt.
The reason I was looking in the logs was that the connection seems to have become "laggy" in the last couple of days and DNS look-ups and website loading seem to take longer than usual so I wanted to see whether my speed was down. With the speeds I have, however, there shouldn't be any noticeable lag, so there must be another explanation. I'll have to see whether something's changed on my PC. Given the quantity of third-party stuff most websites load these days, any delay in DNS resolution could well account for what I see.
Re: What's the Mongolian connection?
18-02-2020 6:52 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Bob Pullen
Plusnet Product Team
If I've been helpful then please give thanks ⤵
Re: What's the Mongolian connection?
19-02-2020 1:54 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Which does raise the question of why you use an apparently unregistered Chinese (Macau) domain name for this purpose.
Re: What's the Mongolian connection?
19-02-2020 5:27 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Replying to myself because I can't find the option to edit my previous post, it seems the problem was DNS-related. Changing to third-party DNS has restored normal working. Is there a fault in PN's DNS at present slowing the response?
Re: What's the Mongolian connection?
21-02-2020 11:08 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@kjpetrie The ACS hostname is a BT address not a Mongolian website.😃
I seem to recall the router displays a truncated version, not the full address. It may be https://pbthdm.bt.motive.com/
I wouldn't worry about it.
Re: What's the Mongolian connection?
22-02-2020 10:07 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@kjpetrie wrote:
Which does raise the question of why you use an apparently unregistered Chinese (Macau) domain name for this purpose.
We're not. The full domain name is https://dbtpnhdmmc.bt.motive.com
It's registered to an address in France, and is owned by Nokia.
Bob Pullen
Plusnet Product Team
If I've been helpful then please give thanks ⤵
Re: What's the Mongolian connection?
22-02-2020 8:35 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Thanks for the clarification. With all the media fuss about Huawei it would be so easy for someone to see these log messages as an indication the Chinese had a back door into your routers. I do think it's silly to truncate a url though, as part of a url is no use to anyone, especially when it's as misleading as this.
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Help with my Plusnet services
- :
- My Router
- :
- Re: What's the Mongolian connection?