hamwong
Occasional Visitor
I am currently using ASUS AC88U with firmware 384.7, I found log have many firewall log that drop packet from 162.125.34.129, and I try whois found IP belongs to dropbox, I don't know who is the real destination client IP, but I am very interest why firewall will drop pack et from dropbox?
P.S. also have packet from apple 17.173.254.223
Oct 29 06:54:05 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=297 TOS=0x00 PREC=0x20 TTL=52 ID=35695 DF PROTO=TCP SPT=443 DPT=12681 SEQ=3426399936 ACK=1744454676 WINDOW=68 RES=0x00 ACK PSH URGP=0
Oct 29 06:54:06 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=297 TOS=0x00 PREC=0x20 TTL=52 ID=35696 DF PROTO=TCP SPT=443 DPT=12681 SEQ=3426399936 ACK=1744454676 WINDOW=68 RES=0x00 ACK PSH URGP=0
Oct 29 06:54:08 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=297 TOS=0x00 PREC=0x20 TTL=52 ID=35697 DF PROTO=TCP SPT=443 DPT=12681 SEQ=3426399936 ACK=1744454676 WINDOW=68 RES=0x00 ACK PSH URGP=0
Oct 29 06:54:11 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=297 TOS=0x00 PREC=0x20 TTL=52 ID=35698 DF PROTO=TCP SPT=443 DPT=12681 SEQ=3426399936 ACK=1744454676 WINDOW=68 RES=0x00 ACK PSH URGP=0
Oct 29 06:54:18 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=297 TOS=0x00 PREC=0x20 TTL=52 ID=35699 DF PROTO=TCP SPT=443 DPT=12681 SEQ=3426399936 ACK=1744454676 WINDOW=68 RES=0x00 ACK PSH URGP=0
Oct 29 06:54:28 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=104 TOS=0x00 PREC=0x20 TTL=52 ID=60808 DF PROTO=TCP SPT=443 DPT=10576 SEQ=4133629555 ACK=2910233941 WINDOW=83 RES=0x00 ACK URGP=0
Oct 29 06:54:30 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=297 TOS=0x00 PREC=0x20 TTL=52 ID=54799 DF PROTO=TCP SPT=443 DPT=11761 SEQ=1311423814 ACK=1531733574 WINDOW=85 RES=0x00 ACK PSH URGP=0
Oct 29 06:54:30 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=297 TOS=0x00 PREC=0x20 TTL=52 ID=54800 DF PROTO=TCP SPT=443 DPT=11761 SEQ=1311423814 ACK=1531733574 WINDOW=85 RES=0x00 ACK PSH URGP=0
Oct 29 06:54:30 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=297 TOS=0x00 PREC=0x20 TTL=52 ID=54801 DF PROTO=TCP SPT=443 DPT=11761 SEQ=1311423814 ACK=1531733574 WINDOW=85 RES=0x00 ACK PSH URGP=0
Oct 29 06:54:31 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=297 TOS=0x00 PREC=0x20 TTL=52 ID=54802 DF PROTO=TCP SPT=443 DPT=11761 SEQ=1311423814 ACK=1531733574 WINDOW=85 RES=0x00 ACK PSH URGP=0
Oct 29 06:54:32 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=296 TOS=0x00 PREC=0x20 TTL=52 ID=35700 DF PROTO=TCP SPT=443 DPT=12681 SEQ=3426399936 ACK=1744454676 WINDOW=68 RES=0x00 ACK URGP=0
Oct 29 06:54:33 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=297 TOS=0x00 PREC=0x20 TTL=52 ID=54803 DF PROTO=TCP SPT=443 DPT=11761 SEQ=1311423814 ACK=1531733574 WINDOW=85 RES=0x00 ACK PSH URGP=0
Oct 29 06:54:37 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=297 TOS=0x00 PREC=0x20 TTL=52 ID=54804 DF PROTO=TCP SPT=443 DPT=11761 SEQ=1311423814 ACK=1531733574 WINDOW=85 RES=0x00 ACK PSH URGP=0
Oct 29 06:54:44 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=297 TOS=0x00 PREC=0x20 TTL=52 ID=54805 DF PROTO=TCP SPT=443 DPT=11761 SEQ=1311423814 ACK=1531733574 WINDOW=85 RES=0x00 ACK PSH URGP=0
O
P.S. also have packet from apple 17.173.254.223
Oct 29 06:54:05 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=297 TOS=0x00 PREC=0x20 TTL=52 ID=35695 DF PROTO=TCP SPT=443 DPT=12681 SEQ=3426399936 ACK=1744454676 WINDOW=68 RES=0x00 ACK PSH URGP=0
Oct 29 06:54:06 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=297 TOS=0x00 PREC=0x20 TTL=52 ID=35696 DF PROTO=TCP SPT=443 DPT=12681 SEQ=3426399936 ACK=1744454676 WINDOW=68 RES=0x00 ACK PSH URGP=0
Oct 29 06:54:08 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=297 TOS=0x00 PREC=0x20 TTL=52 ID=35697 DF PROTO=TCP SPT=443 DPT=12681 SEQ=3426399936 ACK=1744454676 WINDOW=68 RES=0x00 ACK PSH URGP=0
Oct 29 06:54:11 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=297 TOS=0x00 PREC=0x20 TTL=52 ID=35698 DF PROTO=TCP SPT=443 DPT=12681 SEQ=3426399936 ACK=1744454676 WINDOW=68 RES=0x00 ACK PSH URGP=0
Oct 29 06:54:18 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=297 TOS=0x00 PREC=0x20 TTL=52 ID=35699 DF PROTO=TCP SPT=443 DPT=12681 SEQ=3426399936 ACK=1744454676 WINDOW=68 RES=0x00 ACK PSH URGP=0
Oct 29 06:54:28 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=104 TOS=0x00 PREC=0x20 TTL=52 ID=60808 DF PROTO=TCP SPT=443 DPT=10576 SEQ=4133629555 ACK=2910233941 WINDOW=83 RES=0x00 ACK URGP=0
Oct 29 06:54:30 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=297 TOS=0x00 PREC=0x20 TTL=52 ID=54799 DF PROTO=TCP SPT=443 DPT=11761 SEQ=1311423814 ACK=1531733574 WINDOW=85 RES=0x00 ACK PSH URGP=0
Oct 29 06:54:30 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=297 TOS=0x00 PREC=0x20 TTL=52 ID=54800 DF PROTO=TCP SPT=443 DPT=11761 SEQ=1311423814 ACK=1531733574 WINDOW=85 RES=0x00 ACK PSH URGP=0
Oct 29 06:54:30 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=297 TOS=0x00 PREC=0x20 TTL=52 ID=54801 DF PROTO=TCP SPT=443 DPT=11761 SEQ=1311423814 ACK=1531733574 WINDOW=85 RES=0x00 ACK PSH URGP=0
Oct 29 06:54:31 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=297 TOS=0x00 PREC=0x20 TTL=52 ID=54802 DF PROTO=TCP SPT=443 DPT=11761 SEQ=1311423814 ACK=1531733574 WINDOW=85 RES=0x00 ACK PSH URGP=0
Oct 29 06:54:32 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=296 TOS=0x00 PREC=0x20 TTL=52 ID=35700 DF PROTO=TCP SPT=443 DPT=12681 SEQ=3426399936 ACK=1744454676 WINDOW=68 RES=0x00 ACK URGP=0
Oct 29 06:54:33 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=297 TOS=0x00 PREC=0x20 TTL=52 ID=54803 DF PROTO=TCP SPT=443 DPT=11761 SEQ=1311423814 ACK=1531733574 WINDOW=85 RES=0x00 ACK PSH URGP=0
Oct 29 06:54:37 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=297 TOS=0x00 PREC=0x20 TTL=52 ID=54804 DF PROTO=TCP SPT=443 DPT=11761 SEQ=1311423814 ACK=1531733574 WINDOW=85 RES=0x00 ACK PSH URGP=0
Oct 29 06:54:44 kernel: DROP IN=eth0 OUT= MAC=18:31:bf:5b:12:e8:00:00:5e:00:01:85:08:00 SRC=162.125.34.129 DST=203.XXX.XXX.XXX LEN=297 TOS=0x00 PREC=0x20 TTL=52 ID=54805 DF PROTO=TCP SPT=443 DPT=11761 SEQ=1311423814 ACK=1531733574 WINDOW=85 RES=0x00 ACK PSH URGP=0
O