Download the Tom's Hardware App from the App Store
The reference for current tech news
Yes No

Understand Router Logs

Forum Wireless Networking : General Discussion Understand Router Logs

Word :    Username :           
 

I suspect that there is a rogue MAC addresses on my wireless router.

I have identified the MAC addresses of all the devices on my network including the Router itself(A Zyxel) but there is one more there that I cannot identify. Would I be right to suspect a rogue user or is there something I am missing.

Like could my router be recording the MAC of it's next hop out onto the net and putting that in the log?

Below is a log with the offending MAC address.

Any help would be brilliant!



No. Time Source IP Destination IP Note
1|01/25/2012 16:35:06 |192.168.1.2:63407 |74.125.97.38:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
2|01/25/2012 16:35:05 |192.168.1.2:63406 |74.125.97.38:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
3|01/25/2012 16:34:58 |192.168.1.2:63405 |74.125.97.38:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
4|01/25/2012 16:34:50 |192.168.1.2:63404 |74.125.97.38:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
5|01/25/2012 16:34:25 |192.168.1.2:63403 |74.125.97.38:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
6|01/25/2012 16:34:25 |192.168.1.2:63402 |74.125.97.38:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
7|01/25/2012 16:34:25 |192.168.1.2:63401 |86.43.63.50:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
8|01/25/2012 16:34:25 |192.168.1.2:63400 |209.85.143.100:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
9|01/25/2012 16:34:01 |192.168.1.2:63399 |209.85.143.100:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
10|01/25/2012 16:34:01 |192.168.1.2:63398 |209.85.143.100:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
11|01/25/2012 16:34:01 |192.168.1.2:63397 |209.85.143.100:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
12|01/25/2012 16:33:59 |192.168.1.2:63396 |209.85.143.118:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
13|01/25/2012 16:33:59 |192.168.1.2:63395 |209.85.143.118:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
14|01/25/2012 16:33:59 |192.168.1.2:63394 |209.85.143.118:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
15|01/25/2012 16:33:22 |192.168.1.2:63393 |86.43.63.48:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
16|01/25/2012 16:33:22 |192.168.1.2:63392 |86.43.63.48:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
17|01/25/2012 16:33:21 |192.168.1.2:63391 |86.43.63.48:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
18|01/25/2012 16:33:21 |192.168.1.2:63390 |86.43.63.48:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
19|01/25/2012 16:33:20 |192.168.1.2:63389 |86.43.63.48:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
20|01/25/2012 16:33:19 |192.168.1.2:63388 |86.43.63.48:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
21|01/25/2012 16:33:19 |192.168.1.2:63387 |86.43.63.48:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
22|01/25/2012 16:33:19 |192.168.1.2:63386 |86.43.63.48:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
23|01/25/2012 16:33:18 |192.168.1.2:63385 |86.43.63.48:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
24|01/25/2012 16:33:18 |192.168.1.2:63384 |86.43.63.48:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
25|01/25/2012 16:33:18 |192.168.1.2:63383 |86.43.63.48:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
26|01/25/2012 16:33:17 |192.168.1.2:63382 |86.43.63.48:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
27|01/25/2012 16:33:17 |192.168.1.2:63381 |86.43.63.48:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
28|01/25/2012 16:33:17 |192.168.1.2:63380 |86.43.63.48:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
29|01/25/2012 16:33:17 |192.168.1.2:63379 |86.43.63.48:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
30|01/25/2012 16:33:15 |192.168.1.2:63378 |86.43.63.48:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
31|01/25/2012 16:33:15 |192.168.1.2:63377 |86.43.63.48:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
32|01/25/2012 16:33:15 |192.168.1.2:63376 |209.85.143.100:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
33|01/25/2012 16:33:05 |192.168.1.2:63375 |209.85.143.100:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
34|01/25/2012 16:33:05 |192.168.1.2:63374 |209.85.143.100:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
35|01/25/2012 16:33:05 |192.168.1.2:63373 |209.85.143.100:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
36|01/25/2012 16:33:04 |192.168.1.2:63372 |209.85.143.118:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
37|01/25/2012 16:33:04 |192.168.1.2:63371 |209.85.143.118:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
38|01/25/2012 16:33:04 |192.168.1.2:63370 |209.85.143.118:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
39|01/25/2012 16:32:39 |192.168.1.2:63369 |74.125.97.53:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
40|01/25/2012 16:32:29 |192.168.1.2:63368 |74.125.97.53:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
41|01/25/2012 16:32:29 |192.168.1.2:63367 |74.125.97.53:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
42|01/25/2012 16:32:28 |192.168.1.2:63366 |74.125.97.53:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
43|01/25/2012 16:32:28 |192.168.1.2:63365 |74.125.97.53:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
44|01/25/2012 16:32:27 |192.168.1.2:63364 |74.125.97.53:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
45|01/25/2012 16:32:25 |192.168.1.2:63363 |74.125.97.53:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
46|01/25/2012 16:32:25 |192.168.1.2:63362 |74.125.97.53:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
47|01/25/2012 16:32:23 |192.168.1.2:63361 |74.125.97.53:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
48|01/25/2012 16:32:22 |192.168.1.2:63360 |74.125.97.53:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
49|01/25/2012 16:32:22 |192.168.1.2:63359 |74.125.97.53:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
50|01/25/2012 16:32:22 |192.168.1.2:63358 |86.43.63.55:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
51|01/25/2012 16:32:21 |192.168.1.2:63357 |209.85.143.100:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
52|01/25/2012 16:32:09 |192.168.1.2:63356 |209.85.143.100:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
53|01/25/2012 16:32:09 |192.168.1.2:63355 |209.85.143.100:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
54|01/25/2012 16:32:09 |192.168.1.2:63354 |209.85.143.100:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
55|01/25/2012 16:32:08 |192.168.1.2:63353 |209.85.143.118:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
56|01/25/2012 16:32:07 |192.168.1.2:63352 |209.85.143.118:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
57|01/25/2012 16:32:07 |192.168.1.2:63351 |209.85.143.118:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
58|01/25/2012 16:32:04 |192.168.1.2:63350 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
59|01/25/2012 16:31:57 | | |WLAN
WLAN:Client disassociate (MAC:d0dfc736f1a7, wpapsk)
60|01/25/2012 16:31:57 | | |WLAN
WLAN:Client associate to SSID1 (MAC:d0dfc736f1a7, wpapsk)
61|01/25/2012 16:31:48 |192.168.1.2:63349 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
62|01/25/2012 16:31:40 |192.168.1.2:63348 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
63|01/25/2012 16:31:37 |192.168.1.2:63347 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
64|01/25/2012 16:31:31 |192.168.1.2:63346 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
65|01/25/2012 16:31:31 | | |WLAN
WLAN:Client disassociate (MAC:d0dfc736f1a7, wpapsk)
66|01/25/2012 16:31:29 |192.168.1.2:63345 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
67|01/25/2012 16:31:26 |192.168.1.2:63344 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
68|01/25/2012 16:31:25 | | |WLAN
WLAN:Client associate to SSID1 (MAC:d0dfc736f1a7, wpapsk)
69|01/25/2012 16:31:25 | | |WLAN
WLAN:Client disassociate (MAC:d0dfc736f1a7, wpapsk)
70|01/25/2012 16:31:23 |192.168.1.2:63343 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
71|01/25/2012 16:31:22 |192.168.1.2:63342 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
72|01/25/2012 16:31:20 |192.168.1.2:63341 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
73|01/25/2012 16:31:19 | | |WLAN
WLAN:Client associate to SSID1 (MAC:d0dfc736f1a7, wpapsk)
74|01/25/2012 16:31:19 | | |WLAN
WLAN:Client disassociate (MAC:d0dfc736f1a7, wpapsk)
75|01/25/2012 16:31:19 |192.168.1.2:63340 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
76|01/25/2012 16:31:17 |192.168.1.2:63339 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
77|01/25/2012 16:31:16 |192.168.1.2:63338 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
78|01/25/2012 16:31:13 |192.168.1.2:63337 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
79|01/25/2012 16:31:13 | | |WLAN
WLAN:Client associate to SSID1 (MAC:d0dfc736f1a7, wpapsk)
80|01/25/2012 16:31:13 | | |WLAN
WLAN:Client disassociate (MAC:d0dfc736f1a7, wpapsk)
81|01/25/2012 16:31:11 |192.168.1.2:63336 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
82|01/25/2012 16:31:07 | | |WLAN
WLAN:Client associate to SSID1 (MAC:d0dfc736f1a7, wpapsk)
83|01/25/2012 16:31:07 | | |WLAN
WLAN:Client disassociate (MAC:d0dfc736f1a7, wpapsk)
84|01/25/2012 16:31:04 |192.168.1.3:63053 |17.172.232.167:5223 |ACCESS PERMITTED
Peer TCP state out of order, sent TCP RST: TCP
85|01/25/2012 16:31:04 |17.172.232.167:5223 |192.168.1.3:63053 |ACCESS PERMITTED
Peer TCP state out of order, sent TCP RST: TCP
86|01/25/2012 16:31:01 | | |WLAN
WLAN:Client associate to SSID1 (MAC:d0dfc736f1a7, wpapsk)
87|01/25/2012 16:31:01 | | |WLAN
WLAN:Client disassociate (MAC:d0dfc736f1a7, wpapsk)
88|01/25/2012 16:31:00 |192.168.1.2:63335 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
89|01/25/2012 16:30:59 |192.168.1.2:63334 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
90|01/25/2012 16:30:59 |192.168.1.2:63333 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
91|01/25/2012 16:30:59 |192.168.1.2:63332 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
92|01/25/2012 16:30:58 |192.168.1.2:63331 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
93|01/25/2012 16:30:55 |192.168.1.2:63330 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
94|01/25/2012 16:30:55 | | |WLAN
WLAN:Client associate to SSID1 (MAC:d0dfc736f1a7, wpapsk)
95|01/25/2012 16:30:55 |192.168.1.2:63329 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
96|01/25/2012 16:30:54 |192.168.1.2:63328 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
97|01/25/2012 16:30:53 |192.168.1.2:63327 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
98|01/25/2012 16:30:53 |192.168.1.2:63326 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
99|01/25/2012 16:30:52 |192.168.1.2:63325 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
100|01/25/2012 16:30:49 |192.168.1.2:63324 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
101|01/25/2012 16:30:43 |192.168.1.2:63323 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
102|01/25/2012 16:30:41 |192.168.1.2:63322 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
103|01/25/2012 16:30:41 |192.168.1.2:63321 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
104|01/25/2012 16:30:40 |192.168.1.2:63320 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
105|01/25/2012 16:30:40 | | |WLAN
WLAN:Client disassociate (MAC:d0dfc736f1a7, wpapsk)
106|01/25/2012 16:30:40 |192.168.1.2:63319 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
107|01/25/2012 16:30:39 |192.168.1.2:63318 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
108|01/25/2012 16:30:36 |192.168.1.2:63317 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
109|01/25/2012 16:30:32 |192.168.1.2:63316 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
110|01/25/2012 16:30:31 |192.168.1.2:63315 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
111|01/25/2012 16:30:27 |192.168.1.2:63314 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
112|01/25/2012 16:30:25 |192.168.1.2:63313 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
113|01/25/2012 16:30:24 |192.168.1.2:63312 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
114|01/25/2012 16:30:24 |192.168.1.2:63311 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
115|01/25/2012 16:30:22 | | |DHCP
DHCP client connect, IP: 192.168.1.4
116|01/25/2012 16:30:17 |192.168.1.2:63310 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
117|01/25/2012 16:30:17 | | |WLAN
WLAN:Client associate to SSID1 (MAC:d0dfc736f1a7, wpapsk)
118|01/25/2012 16:30:17 | | |WLAN
WLAN:Client disassociate (MAC:d0dfc736f1a7, wpapsk)
119|01/25/2012 16:30:17 |192.168.1.2:63309 |86.43.63.20:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
120|01/25/2012 16:30:16 |192.168.1.2:63308 |209.85.143.100:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
121|01/25/2012 16:30:15 | | |WLAN
WLAN:Client associate to SSID1 (MAC:d0dfc736f1a7, wpapsk)
122|01/25/2012 16:30:15 | | |WLAN
WLAN:Client disassociate (MAC:d0dfc736f1a7, wpapsk)
123|01/25/2012 16:30:10 | | |WLAN
WLAN:Client associate to SSID1 (MAC:d0dfc736f1a7, wpapsk)
124|01/25/2012 16:30:08 |192.168.1.2:63307 |209.85.143.100:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
125|01/25/2012 16:30:07 |192.168.1.2:63306 |209.85.143.100:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
126|01/25/2012 16:30:05 |192.168.1.2:63305 |209.85.143.118:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
127|01/25/2012 16:30:05 |192.168.1.2:63304 |209.85.143.118:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)
128|01/25/2012 16:30:05 |192.168.1.2:63303 |209.85.143.118:80 |ACCESS PERMITTED
Firewall default policy: TCP (L to W)

Reply to keeganb2000
Register or log in to remove.
Tom's Hardware > Forum > Wireless Networking > General Discussion > Understand Router Logs
Go to:

There are 805 identified and unidentified users. To see the list of identified users, Click here.

  • Ask the community now
  • Publish
Ad
They won a badge
Join us in greeting them