[Internet]
<---->
(public ip) [adsl/router] (192.168.10.1)
<---->
(192.168.10.10) [CENTOS] (192.168.2.1)
<---->
[private 192.168.2.xxx network]
I am using iptables instead of firewalld.
Using iptables I have opened few input ports, accepted everything related and established.
On forward chain, I accept everything related and established , and with
iptables -t nat -A POSTROUTING -o $EXTIF (192.168.10.10) -j MASQUERADE
everything is nat-ed.
I believe that with this setup nobody from the outside should know my internal IP address.
Behind centos server on local private network everything works with no problems at all.
In /var/log/messages I have found entries that are coming on centos’s external interface (192.168.10.10) that are not related nor established. Are these entries evidence of attack?
As you can see external IP's want to connect to the centos using ports 80, 443 or 993. Should I be warried?
http://pastebin.com/9Ke6g7wFMar 10 09:03:55 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=23.206.93.151 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=53 ID=36435 DF PROTO=TCP SPT=443 DPT=49319 WINDOW=0 RES=0x
Mar 10 09:03:55 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=23.206.93.151 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=53 ID=36436 DF PROTO=TCP SPT=443 DPT=49319 WINDOW=0 RES=0x
Mar 10 09:43:34 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=31.13.93.36 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=85 ID=6798 DF PROTO=TCP SPT=443 DPT=63939 WINDOW=0 RES=0x00
Mar 10 09:43:34 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=31.13.93.36 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=85 ID=6799 DF PROTO=TCP SPT=443 DPT=63939 WINDOW=0 RES=0x00
Mar 10 10:13:20 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=208.117.229.248 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=60 ID=60740 PROTO=TCP SPT=443 DPT=49648 WINDOW=0 RES=0x0
Mar 10 10:13:20 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=208.117.229.248 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=60 ID=60741 PROTO=TCP SPT=443 DPT=49648 WINDOW=0 RES=0x0
Mar 10 10:13:20 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=208.117.229.248 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=60 ID=60742 PROTO=TCP SPT=443 DPT=49648 WINDOW=0 RES=0x0
Mar 10 10:13:20 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=172.217.19.168 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=55 ID=50751 PROTO=TCP SPT=443 DPT=49647 WINDOW=0 RES=0x00
Mar 10 10:13:20 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=172.217.19.168 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=55 ID=50752 PROTO=TCP SPT=443 DPT=49647 WINDOW=0 RES=0x00
Mar 10 10:13:20 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=172.217.19.168 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=55 ID=50753 PROTO=TCP SPT=443 DPT=49647 WINDOW=0 RES=0x00
Mar 10 10:17:46 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=95.101.39.32 DST=192.168.10.10 LEN=1462 TOS=0x00 PREC=0x00 TTL=58 ID=53560 DF PROTO=TCP SPT=80 DPT=52691 WINDOW=1080 RES
Mar 10 10:17:46 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=95.101.39.32 DST=192.168.10.10 LEN=1462 TOS=0x00 PREC=0x00 TTL=58 ID=53570 DF PROTO=TCP SPT=80 DPT=52691 WINDOW=1080 RES
Mar 10 10:17:46 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=95.101.39.32 DST=192.168.10.10 LEN=1462 TOS=0x00 PREC=0x00 TTL=58 ID=53572 DF PROTO=TCP SPT=80 DPT=52691 WINDOW=1080 RES
Mar 10 10:52:31 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=54.230.44.88 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=244 ID=60102 DF PROTO=TCP SPT=80 DPT=62186 WINDOW=0 RES=0x0
Mar 10 10:52:49 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=208.117.229.246 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=60 ID=12790 PROTO=TCP SPT=80 DPT=62194 WINDOW=0 RES=0x00
Mar 10 10:53:10 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=91.228.166.91 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=55 ID=45208 DF PROTO=TCP SPT=80 DPT=62340 WINDOW=0 RES=0x0
Mar 10 10:53:10 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=91.228.166.91 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=55 ID=45209 DF PROTO=TCP SPT=80 DPT=62341 WINDOW=0 RES=0x0
Mar 10 11:16:12 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=208.117.229.251 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=60 ID=30776 PROTO=TCP SPT=443 DPT=52014 WINDOW=0 RES=0x0
Mar 10 11:16:12 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=208.117.229.251 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=60 ID=30778 PROTO=TCP SPT=443 DPT=52014 WINDOW=0 RES=0x0
Mar 10 11:16:12 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=208.117.229.251 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=60 ID=30779 PROTO=TCP SPT=443 DPT=52014 WINDOW=0 RES=0x0
Mar 10 12:29:45 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=64.233.166.109 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=43 ID=61108 PROTO=TCP SPT=993 DPT=49546 WINDOW=0 RES=0x00
Mar 10 12:29:45 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=64.233.166.109 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=43 ID=61109 PROTO=TCP SPT=993 DPT=49546 WINDOW=0 RES=0x00
Mar 10 12:29:45 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=64.233.166.109 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=43 ID=61110 PROTO=TCP SPT=993 DPT=49546 WINDOW=0 RES=0x00
Mar 10 12:29:45 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=64.233.166.109 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=43 ID=61111 PROTO=TCP SPT=993 DPT=49546 WINDOW=0 RES=0x00
Mar 10 12:29:45 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=64.233.166.109 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=43 ID=61112 PROTO=TCP SPT=993 DPT=49546 WINDOW=0 RES=0x00
Mar 10 12:29:45 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=64.233.166.109 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=43 ID=61113 PROTO=TCP SPT=993 DPT=49546 WINDOW=0 RES=0x00
Mar 10 12:29:45 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=64.233.166.109 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=43 ID=61114 PROTO=TCP SPT=993 DPT=49546 WINDOW=0 RES=0x00
Mar 10 12:29:45 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=64.233.166.109 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=43 ID=61115 PROTO=TCP SPT=993 DPT=49546 WINDOW=0 RES=0x00
Mar 10 15:10:42 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=184.24.198.121 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=58 ID=45404 DF PROTO=TCP SPT=443 DPT=62210 WINDOW=0 RES=0
Mar 10 15:10:42 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=184.24.198.121 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=58 ID=45406 DF PROTO=TCP SPT=443 DPT=62210 WINDOW=0 RES=0
Mar 10 15:19:49 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=216.58.208.200 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=55 ID=17895 PROTO=TCP SPT=443 DPT=56967 WINDOW=0 RES=0x00
Mar 10 15:19:49 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=216.58.208.200 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=55 ID=17896 PROTO=TCP SPT=443 DPT=56967 WINDOW=0 RES=0x00
Mar 10 15:19:50 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=208.117.229.247 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=60 ID=51843 PROTO=TCP SPT=443 DPT=56968 WINDOW=0 RES=0x0
Mar 10 15:19:50 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=208.117.229.247 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=60 ID=51844 PROTO=TCP SPT=443 DPT=56968 WINDOW=0 RES=0x0
Mar 10 15:19:50 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=208.117.229.247 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=60 ID=51845 PROTO=TCP SPT=443 DPT=56968 WINDOW=0 RES=0x0
Mar 10 15:20:20 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=172.217.21.202 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=57 ID=4386 PROTO=TCP SPT=443 DPT=56964 WINDOW=0 RES=0x00
Mar 10 15:20:20 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=172.217.21.202 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=57 ID=4387 PROTO=TCP SPT=443 DPT=56964 WINDOW=0 RES=0x00
Mar 10 15:20:20 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=172.217.21.202 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=57 ID=4389 PROTO=TCP SPT=443 DPT=56964 WINDOW=0 RES=0x00
Mar 10 15:58:50 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=172.217.22.74 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=58 ID=49070 PROTO=TCP SPT=443 DPT=57089 WINDOW=0 RES=0x00
Mar 10 15:58:51 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=216.58.198.200 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=55 ID=17885 PROTO=TCP SPT=443 DPT=57093 WINDOW=0 RES=0x00
Mar 10 15:58:51 server kernel: IN=enp1s6 OUT= MAC=00:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:00 SRC=216.58.198.200 DST=192.168.10.10 LEN=40 TOS=0x00 PREC=0x00 TTL=55 ID=17888 PROTO=TCP SPT=443 DPT=57093 WINDOW=0 RES=0x00