2013/01/02

Protocol digging

The netgear DGND3300 will log certain things to a remote listening syslogd, but they don't document facilities/priorities which makes it a lot less useful.

So from wireshark:

  1. auth.info logins/login attempts
  2. local0.warning external probes on the firewall (rule match)
  3. syslog.info ntp requests to time-g.netgear.com (weird facility)
  4. syslog.notice ddns requests and outcomes