Router log question

I have tried searching back in this group from Dec 2003 for the answer to my question (based on a subject search) with no success.

My question to you is this;

Does a (wireless) connection in my NAT routers log (SMC2404WBR) indicate a successful connection to my LAN or just a connection to the router on the outside of the limited security it offers? My router is set up to use a WEP key. Unfortunately I use a smaller key size to allow access to the internet by my PDA. I might have to re-evaluate the level of security I am applying and forgo allowing the PDA access. I do secure each individual PC using a software firewall and file shares on sensitive machines using MAC addresses (I realize this is not foolproof but it does add a little more security).

I think you in advance for your time.

Reply to
-Lone_Wolf-
Loading thread data ...

If your router is the DHCP server, yes, you'll see a log when the box renews its ip. You can check the DHCP table also to see what boxes are connected.

Reply to
maybenot

"maybenot" wrote in news:sjnjf.96$gm2.52@trndny03:

If machine is using a Static IP on the router, it will never be in the DHCP table since it's not a DHCP IP. If the router does have a syslog, then he'll be able to see in the logs the remote IP traffic is coming from that's being blocked. He'll see the LAN IP traffic is being sent from static or DHCP IP and the destination IP the traffic is being sent to.

Duane :)

Reply to
Duane Arnold

As Duane mentioned I use static IP's on my LAN so there is no DHCP activity on the LAN side of the router. The activity in question is on the outside (or so I assume).

Here is a sample of the log (names have been changed to protect the innocent);

Nov/30/2005 03:18:26 DHCP Receive IP:##.##.85.17 ##.##.85.17 Nov/30/2005 03:18:26 DHCP Request ##.##.85.17 Nov/29/2005 22:21:15 Wireless PC connected 00-02-3A-2C-11-1C Nov/29/2005 22:20:00 Wireless PC connected 00-02-3A-2C-11-1C Nov/29/2005 12:02:07 Wireless PC connected 00-01-4F-09-E7-99 Nov/29/2005 03:18:27 DHCP Receive IP:##.##.85.17 ##.##.85.17 Nov/29/2005 03:18:27 DHCP Request ##.##.85.17 Nov/28/2005 03:18:26 DHCP Receive IP:##.##.85.17 ##.##.85.17 Nov/28/2005 03:18:26 DHCP Request ##.##.85.17 Nov/27/2005 20:09:49 Wireless PC connected 00-01-4F-09-E7-99...

I know the MAC address represented by "00-01-4F-09-E7-99" is my laptop but there are two other MAC addresses that I know are not mine. I am assuming this is acknowledgment of a connection to the router not of being allowed to pass thru?

Reply to
-Lone_Wolf-

Duane is correct, you'll not see LAN ip's that is assigned static. However, if you assigned ip reservation via DHCP table per MAC then it will. One way you can also check roque ip's is to check the outbound logs. If you see activity in the log for non ip you assigned then you know there's an alien.

Reply to
maybenot

you should be able to set the router to DENY access to

00-02-3A-2C-11-1C
Reply to
Jeff B

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.