Sat Jan 18 05:37:16 2025 daemon.debug ocserv[10466]: main: added 1 points (total 1) for IP '79.124.49.202' to ban list
Sat Jan 18 05:37:16 2025 daemon.debug ocserv[10546]: sec-mod: received request from pid 30231 and uid 0
Sat Jan 18 05:37:16 2025 daemon.debug ocserv[10546]: sec-mod: cmd [size=38] sm: sign hash
Sat Jan 18 05:37:16 2025 daemon.debug ocserv[30231]: worker: 79.124.49.202 accepted connection
Sat Jan 18 05:37:16 2025 daemon.notice ocserv[30231]: worker: 79.124.49.202 warning: Received record packet of unknown type 3
Sat Jan 18 05:37:16 2025 daemon.warn ocserv[30231]: GnuTLS error (at worker-vpn.c:889): An unexpected TLS packet was received.
Sat Jan 18 05:37:16 2025 daemon.err ocserv[10466]: NLM query failed No such file or directory
Sat Jan 18 05:37:16 2025 daemon.debug ocserv[10466]: main: queue_length retval:-1 rqueue:0 wqueue:0
Sat Jan 18 05:37:16 2025
daemon.info ocserv[10466]: main: delaying accepts for 100 ms
Sat Jan 18 05:37:16 2025 daemon.debug ocserv[10466]: main:79.124.49.202:60887 worker terminated
Sat Jan 18 05:37:16 2025 daemon.debug ocserv[10466]: main:79.124.49.202:60887 user disconnected (reason: unspecified, rx: 0, tx: 0)
先说说我这边的情况,ImmortalWrt ,有公网,开启 DDNS ,防火墙禁 ping 禁 IGMP ,web 管理页面不在外网侧开启,从外面连进去唯一的办法就是 openconnect VPN ,我通常使用证书登入,留了个密码登入方式,但密码相当复杂,不大存在被爆破的可能。
日志信息应该是来自 ocserv ,也就是 openconnect VPN 插件。
第一条这个:
Sat Jan 18 05:37:16 2025 daemon.debug ocserv[10466]: main: added 1 points (total 1) for IP '79.124.49.202' to ban list
按照理解,应该'79.124.49.202'这个 IP 被封锁了是吧?
但为何在:
Sat Jan 18 05:37:16 2025 daemon.debug ocserv[30231]: worker: 79.124.49.202 accepted connection
这里,会有一个 accepted connection 的提示?