May 30, 20179 yr Hi guys, Version: 6.3.3 iftop shows my rig to "call" everywhere in the world - it looks to me as it is torrent, but it is not as the docker is off, and it's actually a new built so I never ran torrent of it. So, all Dockers are currently turned off, following plugins are installed: CA Auto Update Applications CA Backup / Restore Appdata CA Cleanup Appdata Community Applications Dynamix Active Streams Dynamix Auto Fan Control Dynamix Cache Directories Dynamix S3 Sleep Dynamix Schedules Dynamix SSD TRIM Dynamix System Information Dynamix webGui Nerd Tools unRAID Server OS Here is a copy/paste of a current iftop: Tower => DiskStation 186kB 422kB 338kB <= 36.1MB 58.4MB 57.8MB Tower => setup.ubnt.com 319B 339B 305B <= 706B 726B 623B 239.255.255.250 => setup.ubnt.com 0B 0B 0B <= 80B 48B 49B Tower => 1F2E3E04.catv.pool.telekom.hu 0B 13B 18B <= 0B 34B 18B Tower => host-79-121-40-197.kabelnet.hu 0B 13B 5B <= 0B 34B 13B Tower => 111.92.57.220 0B 34B 13B <= 0B 13B 5B Tower => 249.64.uzpak.uz 0B 34B 13B <= 0B 13B 5B Tower => 1.242.35.25 0B 32B 12B <= 0B 13B 5B Tower => host21-77-dynamic.180-80-r.retail.telecomitalia.it 0B 32B 12B <= 0B 13B 5B Tower => 112.165.122.246 0B 32B 12B <= 0B 13B 5B Tower => 80.217.224.159.triolan.net 0B 32B 12B <= 0B 13B 5B Anyone has an idea on how to find out what's causing all those connections?
May 30, 20179 yr What is your tower's IP address, and did you change anything in your router referencing it?
May 30, 20179 yr Author Local IP is 192.168.1.235 - router is set to forward the webinterface port (which I switched to 5000), nothing else.
May 30, 20179 yr 2 minutes ago, henkedk said: router is set to forward the webinterface port Don't do that. emhttp, the custom piece of software that runs the array and the webgui, is NOT secure for internet facing. If you want to remotely manage your server, set up a proper incoming VPN.
May 30, 20179 yr Author Forward only is accepted from my office IP in the router - even if it is not as secure as a VPN, it is more secure than an open connection to the world. This still doens't explain all those connections though.
May 31, 20179 yr Forward only is accepted from my office IP in the router - even if it is not as secure as a VPN, it is more secure than an open connection to the world. This still doens't explain all those connections though.Pick a different port to use for the forward. 5000 is up there on the list of what never to use for something you want to disguise/hide. Google the tcp port before selecting one. Wireshark, Snort or an equivalent can help identify the what and where from regarding your traffic.Sent from my ASUS_Z00AD using Tapatalk
Archived
This topic is now archived and is closed to further replies.