What's new

Skynet Skynet - Router Firewall & Security Enhancements

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Thanks! Eventually I'll have a better idea what this means. So it seems ok to whitelist in Skynet? Maybe just the apps phoning home to check for updates?
 
Thanks! Eventually I'll have a better idea what this means. So it seems ok to whitelist in Skynet? Maybe just the apps phoning home to check for updates?

Should be okay, CDN's host tens of thousands of websites so even if %99 of those websites are legitimate, it only takes one to get the whole server blacklisted.
 
One other question. I noticed that after turning on Skynet that I'm not getting any hits on aiProtect. Can I take that to mean that nothing is making it through Skynet to aiProtect so far?
 
One other question. I noticed that after turning on Skynet that I'm not getting any hits on aiProtect. Can I take that to mean that nothing is making it through Skynet to aiProtect so far?

IIRC last I checked traffic was hitting AiProtect first before IPTables rules took effect. Can't say I looked into it too much as there's no great way to test. In any case both work together seamlessly, I generally get about 5 hits per day on average from AiProtect logs.
 
What router?

I do get Two-Way IPS hits on AC56U and AC68U, but not on AC86U.

If you are not getting hits its probably a signature issue or something, works fine on my AC86U.

KveKbeg.png
 
If you are not getting hits its probably a signature issue or something, works fine on my AC86U.
All routers have 2.068, last updated last month.

Where are they stored? Can I compare hashes or do they differ per model/platform?
 
IIRC last I checked traffic was hitting AiProtect first before IPTables rules took effect. Can't say I looked into it too much as there's no great way to test. In any case both work together seamlessly, I generally get about 5 hits per day on average from AiProtect logs.

Interesting. AiProtect is in front. I used to get about 5 hits per day on AiProtect. My signature file is up-to-date. Maybe I'm just lucky now. :)
 
Hi Adamm
should I be concerned on the error message below? Thank you
Skynet: [INFO] Lock File Detected (save) (pid=6718) - Exiting (cpid=6911)
 
Hi Adamm
should I be concerned on the error message below? Thank you
Skynet: [INFO] Lock File Detected (save) (pid=6718) - Exiting (cpid=6911)

No, that just means a command was already running so it prevented you from running another (in this case it was the save command). Skynet only allows one command at a time in most cases to prevent commands interfering with each-other.
 
Would there be a way of capturing which apps are involved in the top 10 or 20 outbound / inbound blocks?

No, Skynet isn't an IPS engine, it can only tell you what the local IP is, its then up to the user to make the distinction of whats being blocked.
 
Hi Adam Im on 6.1.8. I noticed that Im getting only INBOUND blocks - no OUTBOUND.
Anyone else experiencing this?
 
Hi Adam Im on 6.1.8. I noticed that Im getting only INBOUND blocks - no OUTBOUND.
Anyone else experiencing this?

You may only have inbound filtering enabled, use the install command and make sure you select "All Traffic". Besides that, outbound blocks aren't as common unless you use things like P2P (torrenting).
 
You may only have inbound filtering enabled, use the install command and make sure you select "All Traffic". Besides that, outbound blocks aren't as common unless you use things like P2P (torrenting).
Thanks Adam I had both selected and yes with Bit Torrent download I am seeing OUTBOUND blocking. Thank you
 

Similar threads

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top