Linux firewall users, please assist...

The_Unbeliever

Honorary Master
Joined
Apr 19, 2005
Messages
103,193
Reaction score
10,233
Location
Nkaaaaandla
Whether you're using Smoothwall, IPCop, or any Linux firewall which is able to log errors and other messages from the pppd daemon, you can help here.

This pertains to users with ADSL (fixed-wire) lines only.

I want to know whether your pppd log also contains the following message(s) :

Code:
02:12:24 pppoe Session 9208 terminated -- received PADT from peer
02:12:24 pppoe Sent PADT
02:12:24 pppd Modem hangup
02:12:24 pppd Connection terminated.
02:12:24 pppd Using interface ppp0
02:12:24 pppd Connect: ppp0 <--> /dev/ttyp0
02:12:39 pppoe PPP session is 48006 (0xbb86)
02:12:41 pppd PAP authentication succeeded
02:12:41 pppd kernel does not support PPP filtering
02:12:41 pppd local IP address 165.146.43.xxx
02:12:41 pppd remote IP address 165.146.40.1
02:12:41 pppd primary DNS address 196.43.45.190
02:12:41 pppd secondary DNS address 196.43.46.190

Regards

Libs
 
Mine looks pretty similiar - running Slack with iptables.

Code:
16:56:44 firewall kernel: CSLIP: code copyright 1989 Regents of the University of California
16:56:44 firewall kernel: PPP generic driver version 2.4.2
16:56:44 firewall pppd[445]: pppd 2.4.4 started by root, uid 0
16:56:44 firewall pppd[445]: Using interface ppp0
16:56:44 firewall pppd[445]: Connect: ppp0 <--> /dev/pts/1
16:56:59 firewall pppoe[447]: PPP session is 16039 (0x3ea7)
16:57:00 firewall pppd[445]: PAP authentication succeeded
16:57:00 firewall kernel: PPP BSD Compression module registered
16:57:00 firewall pppd[445]: local  IP address 41.240.12.xxx
16:57:00 firewall pppd[445]: remote IP address 41.240.64.1
16:57:00 firewall pppd[445]: primary   DNS address 196.43.50.190
16:57:00 firewall pppd[445]: secondary DNS address 196.43.53.190
16:57:05 firewall ntpd[555]: ntpd [email protected] Tue Aug  8 04:20:31 UTC 2006 (1)
16:57:06 firewall ntpd[556]: precision = 1.000 usec
16:57:06 firewall ntpd[556]: Listening on interface wildcard, 0.0.0.0#123 Disabled
16:57:06 firewall ntpd[556]: Listening on interface lo, 127.0.0.1#123 Enabled
16:57:06 firewall ntpd[556]: Listening on interface eth0, 10.1.1.1#123 Enabled
16:57:06 firewall ntpd[556]: Listening on interface eth2, 172.16.0.1#123 Enabled
16:57:06 firewall ntpd[556]: Listening on interface ppp0, 41.240.12.xxx#123 Enabled
16:57:06 firewall ntpd[556]: kernel time sync status 0040
16:57:06 firewall ntpd[556]: frequency initialized 40.211 PPM from /etc/ntp/drift
16:57:06 firewall squid[560]: Squid Parent: child process 562 started
16:57:06 firewall squid[562]: Process ID 562
16:57:06 firewall squid[562]: With 1024 file descriptors available
 
Hi Libs
I disconnected and reconnected (from the smoothwall console) just for you :)

Code:
Aug 10 18:11:49 smoothwall pppd[8059]: Terminating on signal 15
Aug 10 18:11:49 smoothwall pppd[8059]: Connect time 13488.0 minutes.
Aug 10 18:11:49 smoothwall pppd[8059]: Sent 410351879 bytes, received 3152632524 bytes.
Aug 10 18:11:49 smoothwall pppd[8059]: Connection terminated.
Aug 10 18:11:49 smoothwall pppoe[8060]: read (asyncReadFromPPP): Session 31890: Input/output error
Aug 10 18:11:49 smoothwall pppoe[8060]: Sent PADT
Aug 10 18:11:50 smoothwall smoothwall: PPP has gone down on ppp0
Aug 10 18:11:52 smoothwall pppd[8059]: Exit.
Aug 10 18:11:55 smoothwall pppd[13428]: pppd 2.4.4 started by root, uid 0
Aug 10 18:11:55 smoothwall pppd[13428]: Using interface ppp0
Aug 10 18:11:55 smoothwall pppd[13428]: Connect: ppp0 <--> /dev/ttyp0
Aug 10 18:12:10 smoothwall pppoe[13429]: PPP session is 14158 (0x374e)
Aug 10 18:12:12 smoothwall pppd[13428]: PAP authentication succeeded
Aug 10 18:12:12 smoothwall pppd[13428]: kernel does not support PPP filtering
Aug 10 18:12:12 smoothwall pppd[13428]: local  IP address 41.244.xxx.xxx
Aug 10 18:12:12 smoothwall pppd[13428]: remote IP address 41.241.xxx.xxx
Aug 10 18:12:12 smoothwall pppd[13428]: primary   DNS address 196.43.45.190
Aug 10 18:12:12 smoothwall pppd[13428]: secondary DNS address 196.43.46.190
Aug 10 18:12:13 smoothwall smoothwall: PPP has gone up on ppp0

No mention of "from peer", although the local does say "Sent PADT" at the end of the disconnect, same as in yours.
 
Last edited:
And then I unplugged my phone line:

Code:
Aug 10 18:21:12 smoothwall pppd[13428]: No response to 3 echo-requests
Aug 10 18:21:12 smoothwall pppd[13428]: Serial link appears to be disconnected.
Aug 10 18:21:12 smoothwall pppd[13428]: Connect time 9.0 minutes.
Aug 10 18:21:12 smoothwall pppd[13428]: Sent 1021447 bytes, received 6149139 bytes.
Aug 10 18:21:12 smoothwall smoothwall: PPP has gone down on ppp0
Aug 10 18:21:18 smoothwall pppd[13428]: Connection terminated.
Aug 10 18:21:18 smoothwall pppoe[13429]: read (asyncReadFromPPP): Session 14158: Input/output error
Aug 10 18:21:18 smoothwall pppoe[13429]: Sent PADT
Aug 10 18:21:18 smoothwall pppd[13428]: Modem hangup
Aug 10 18:21:18 smoothwall pppd[13428]: Using interface ppp0
Aug 10 18:21:18 smoothwall pppd[13428]: Connect: ppp0 <--> /dev/ttyp0
Aug 10 18:21:53 smoothwall pppoe[13843]: Timeout waiting for PADO packets
Aug 10 18:21:53 smoothwall pppd[13428]: Modem hangup
Aug 10 18:21:53 smoothwall pppd[13428]: Connection terminated.
Aug 10 18:21:53 smoothwall pppd[13428]: Using interface ppp0
Aug 10 18:21:53 smoothwall pppd[13428]: Connect: ppp0 <--> /dev/ttyp0
Aug 10 18:21:53 smoothwall pppoe[13866]: PPP session is 21822 (0x553e)
Aug 10 18:21:58 smoothwall pppd[13428]: PAP authentication succeeded
Aug 10 18:21:58 smoothwall pppd[13428]: kernel does not support PPP filtering
Aug 10 18:21:59 smoothwall pppd[13428]: local  IP address 41.243.118.217
Aug 10 18:21:59 smoothwall pppd[13428]: remote IP address 41.241.192.1
Aug 10 18:21:59 smoothwall pppd[13428]: primary   DNS address 196.43.45.190
Aug 10 18:21:59 smoothwall pppd[13428]: secondary DNS address 196.43.46.190
Aug 10 18:21:59 smoothwall smoothwall: PPP has gone up on ppp0
 
02:12:24 pppoe Session 9208 terminated -- received PADT from peer
02:12:24 pppoe Sent PADT

To my knowledge, that is a PPP session reset packet which is sent by your ISP to your router to disconnect your current session.
 
Yes, but only the 'received PADT' line. The second refers to a PADT sent by the logging device (the smoothwall) - as you'll see, that also appears in circumstances like being terminated by the user.
 
From IPCop disconnect -> connect

Code:
Aug 11 10:35:02 ipcop ipcop: Dialling mick.
Aug 11 10:35:03 ipcop pppd[10998]: pppd 2.4.2 started by root, uid 0
Aug 11 10:35:03 ipcop pppd[10998]: using channel 4
Aug 11 10:35:03 ipcop pppd[10998]: Using interface ppp0
Aug 11 10:35:03 ipcop pppd[10998]: Connect: ppp0 <--> /dev/pts/0
Aug 11 10:35:03 ipcop pppoe[10999]: PADS: Service-Name: ''
Aug 11 10:35:03 ipcop pppoe[10999]: PPP session is 30303 (0x765f)
Aug 11 10:35:03 ipcop pppd[10998]: rcvd [LCP ConfReq id=0x1 <mru 1492> <auth pap> <magic 0x40216ef1>]
Aug 11 10:35:03 ipcop pppd[10998]: sent [LCP ConfReq id=0x1 <mru 1492> <magic 0xd8771029>]
Aug 11 10:35:03 ipcop pppd[10998]: sent [LCP ConfAck id=0x1 <mru 1492> <auth pap> <magic 0x40216ef1>]
Aug 11 10:35:03 ipcop pppd[10998]: rcvd [LCP ConfAck id=0x1 <mru 1492> <magic 0xd8771029>]
Aug 11 10:35:03 ipcop pppd[10998]: sent [LCP EchoReq id=0x0 magic=0xd8771029]
Aug 11 10:35:03 ipcop pppd[10998]: sent [PAP AuthReq id=0x1 user="online******@dsl512telkomsa.net" password=<hidden>]
Aug 11 10:35:03 ipcop pppd[10998]: rcvd [LCP EchoRep id=0x0 magic=0x40216ef1]
Aug 11 10:35:03 ipcop pppd[10998]: rcvd [PAP AuthAck id=0x1 ""]
Aug 11 10:35:03 ipcop pppd[10998]: PAP authentication succeeded
Aug 11 10:35:03 ipcop pppd[10998]: sent [IPCP ConfReq id=0x1 <addr 0.0.0.0> <ms-dns1 0.0.0.0> <ms-dns3 0.0.0.0>]
Aug 11 10:35:03 ipcop pppd[10998]: rcvd [IPCP ConfReq id=0x1 <addr 41.242.128.1>]
Aug 11 10:35:03 ipcop pppd[10998]: sent [IPCP ConfAck id=0x1 <addr 41.242.128.1>]
Aug 11 10:35:03 ipcop pppd[10998]: rcvd [IPCP ConfNak id=0x1 <addr 41.242.140.200> <ms-dns1 196.43.50.190> <ms-dns3 196.43.53.190>]
Aug 11 10:35:03 ipcop pppd[10998]: sent [IPCP ConfReq id=0x2 <addr 41.242.140.200> <ms-dns1 196.43.50.190> <ms-dns3 196.43.53.190>]
Aug 11 10:35:03 ipcop pppd[10998]: rcvd [IPCP ConfAck id=0x2 <addr 41.242.140.200> <ms-dns1 196.43.50.190> <ms-dns3 196.43.53.190>]
Aug 11 10:35:03 ipcop pppd[10998]: local  IP address 41.242.140.***
Aug 11 10:35:03 ipcop pppd[10998]: remote IP address 41.242.128.1
Aug 11 10:35:03 ipcop pppd[10998]: primary   DNS address 196.43.50.190
Aug 11 10:35:03 ipcop pppd[10998]: secondary DNS address 196.43.53.190
Aug 11 10:35:03 ipcop pppd[10998]: Script /etc/ppp/ip-up started (pid 11001)
Aug 11 10:35:04 ipcop ipcop: PPP has gone up on ppp0
Aug 11 10:35:05 ipcop dnsmasq[11051]: started, version 2.38 cachesize 150
@
 
Last edited:
Top
Sign up to the MyBroadband newsletter
X