External IP address in samba share logs





.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty{ height:90px;width:728px;box-sizing:border-box;
}







0















I have a samba share with debian jessie and everything works fine. But in the logs file I get attempts from external ip. I have checked and I don't have any ports opened. I don't know what could it be, and I am worried that I have some security issues.



It's a wifi modem-router. The lan is set up with IP 192.168.1.1 and
subnet mask 255.255.255.0 (dhcp for all devices except for the samba share which has a static ip). The samba server requires a user/password (no guest) and you can read and write.










share|improve this question

























  • What do you mean for EXTERNAL? What's your network design? Does it mean you have an internal interface which the share is available?

    – Manuel Florian
    Jan 28 at 22:21











  • I edited the question with the design. The samba share works fine, and from the lan I can read write. What I am afraid of is that someone from outside the lan (that what I mean by external) can download or upload files from the samba server.

    – user991145
    Jan 29 at 0:05


















0















I have a samba share with debian jessie and everything works fine. But in the logs file I get attempts from external ip. I have checked and I don't have any ports opened. I don't know what could it be, and I am worried that I have some security issues.



It's a wifi modem-router. The lan is set up with IP 192.168.1.1 and
subnet mask 255.255.255.0 (dhcp for all devices except for the samba share which has a static ip). The samba server requires a user/password (no guest) and you can read and write.










share|improve this question

























  • What do you mean for EXTERNAL? What's your network design? Does it mean you have an internal interface which the share is available?

    – Manuel Florian
    Jan 28 at 22:21











  • I edited the question with the design. The samba share works fine, and from the lan I can read write. What I am afraid of is that someone from outside the lan (that what I mean by external) can download or upload files from the samba server.

    – user991145
    Jan 29 at 0:05














0












0








0








I have a samba share with debian jessie and everything works fine. But in the logs file I get attempts from external ip. I have checked and I don't have any ports opened. I don't know what could it be, and I am worried that I have some security issues.



It's a wifi modem-router. The lan is set up with IP 192.168.1.1 and
subnet mask 255.255.255.0 (dhcp for all devices except for the samba share which has a static ip). The samba server requires a user/password (no guest) and you can read and write.










share|improve this question
















I have a samba share with debian jessie and everything works fine. But in the logs file I get attempts from external ip. I have checked and I don't have any ports opened. I don't know what could it be, and I am worried that I have some security issues.



It's a wifi modem-router. The lan is set up with IP 192.168.1.1 and
subnet mask 255.255.255.0 (dhcp for all devices except for the samba share which has a static ip). The samba server requires a user/password (no guest) and you can read and write.







samba






share|improve this question















share|improve this question













share|improve this question




share|improve this question








edited Jan 29 at 0:03







user991145

















asked Jan 28 at 20:46









user991145user991145

11




11













  • What do you mean for EXTERNAL? What's your network design? Does it mean you have an internal interface which the share is available?

    – Manuel Florian
    Jan 28 at 22:21











  • I edited the question with the design. The samba share works fine, and from the lan I can read write. What I am afraid of is that someone from outside the lan (that what I mean by external) can download or upload files from the samba server.

    – user991145
    Jan 29 at 0:05



















  • What do you mean for EXTERNAL? What's your network design? Does it mean you have an internal interface which the share is available?

    – Manuel Florian
    Jan 28 at 22:21











  • I edited the question with the design. The samba share works fine, and from the lan I can read write. What I am afraid of is that someone from outside the lan (that what I mean by external) can download or upload files from the samba server.

    – user991145
    Jan 29 at 0:05

















What do you mean for EXTERNAL? What's your network design? Does it mean you have an internal interface which the share is available?

– Manuel Florian
Jan 28 at 22:21





What do you mean for EXTERNAL? What's your network design? Does it mean you have an internal interface which the share is available?

– Manuel Florian
Jan 28 at 22:21













I edited the question with the design. The samba share works fine, and from the lan I can read write. What I am afraid of is that someone from outside the lan (that what I mean by external) can download or upload files from the samba server.

– user991145
Jan 29 at 0:05





I edited the question with the design. The samba share works fine, and from the lan I can read write. What I am afraid of is that someone from outside the lan (that what I mean by external) can download or upload files from the samba server.

– user991145
Jan 29 at 0:05










1 Answer
1






active

oldest

votes


















1














Does your internet service come through a router? Most home routers have a web interface which you can only access from inside your network. Use your web browser and the router's IP address as the URL. For example:



http://192.168.1.1/


You'll need a username and password, which may be printed on a sticker on the router. Or google "default verizon router username password" or similar.



Once you're in, click on "Firewall Settings" or similar. Mine has a "Security Log" menu item that shows what inbound traffic was accepted or blocked.



From there you should be able to setup rules to block traffic by port or by other features.






share|improve this answer
























  • Yes, it is through a router, and I have the username / password. The log was disabled by default, and as far as I am concerned port 139 and 445 are not open

    – user991145
    Jan 29 at 0:11












Your Answer








StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "3"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});

function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});


}
});














draft saved

draft discarded


















StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f1399414%2fexternal-ip-address-in-samba-share-logs%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown

























1 Answer
1






active

oldest

votes








1 Answer
1






active

oldest

votes









active

oldest

votes






active

oldest

votes









1














Does your internet service come through a router? Most home routers have a web interface which you can only access from inside your network. Use your web browser and the router's IP address as the URL. For example:



http://192.168.1.1/


You'll need a username and password, which may be printed on a sticker on the router. Or google "default verizon router username password" or similar.



Once you're in, click on "Firewall Settings" or similar. Mine has a "Security Log" menu item that shows what inbound traffic was accepted or blocked.



From there you should be able to setup rules to block traffic by port or by other features.






share|improve this answer
























  • Yes, it is through a router, and I have the username / password. The log was disabled by default, and as far as I am concerned port 139 and 445 are not open

    – user991145
    Jan 29 at 0:11
















1














Does your internet service come through a router? Most home routers have a web interface which you can only access from inside your network. Use your web browser and the router's IP address as the URL. For example:



http://192.168.1.1/


You'll need a username and password, which may be printed on a sticker on the router. Or google "default verizon router username password" or similar.



Once you're in, click on "Firewall Settings" or similar. Mine has a "Security Log" menu item that shows what inbound traffic was accepted or blocked.



From there you should be able to setup rules to block traffic by port or by other features.






share|improve this answer
























  • Yes, it is through a router, and I have the username / password. The log was disabled by default, and as far as I am concerned port 139 and 445 are not open

    – user991145
    Jan 29 at 0:11














1












1








1







Does your internet service come through a router? Most home routers have a web interface which you can only access from inside your network. Use your web browser and the router's IP address as the URL. For example:



http://192.168.1.1/


You'll need a username and password, which may be printed on a sticker on the router. Or google "default verizon router username password" or similar.



Once you're in, click on "Firewall Settings" or similar. Mine has a "Security Log" menu item that shows what inbound traffic was accepted or blocked.



From there you should be able to setup rules to block traffic by port or by other features.






share|improve this answer













Does your internet service come through a router? Most home routers have a web interface which you can only access from inside your network. Use your web browser and the router's IP address as the URL. For example:



http://192.168.1.1/


You'll need a username and password, which may be printed on a sticker on the router. Or google "default verizon router username password" or similar.



Once you're in, click on "Firewall Settings" or similar. Mine has a "Security Log" menu item that shows what inbound traffic was accepted or blocked.



From there you should be able to setup rules to block traffic by port or by other features.







share|improve this answer












share|improve this answer



share|improve this answer










answered Jan 28 at 22:21









Ken JacksonKen Jackson

22112




22112













  • Yes, it is through a router, and I have the username / password. The log was disabled by default, and as far as I am concerned port 139 and 445 are not open

    – user991145
    Jan 29 at 0:11



















  • Yes, it is through a router, and I have the username / password. The log was disabled by default, and as far as I am concerned port 139 and 445 are not open

    – user991145
    Jan 29 at 0:11

















Yes, it is through a router, and I have the username / password. The log was disabled by default, and as far as I am concerned port 139 and 445 are not open

– user991145
Jan 29 at 0:11





Yes, it is through a router, and I have the username / password. The log was disabled by default, and as far as I am concerned port 139 and 445 are not open

– user991145
Jan 29 at 0:11


















draft saved

draft discarded




















































Thanks for contributing an answer to Super User!


  • Please be sure to answer the question. Provide details and share your research!

But avoid



  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.


To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f1399414%2fexternal-ip-address-in-samba-share-logs%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

Paul Cézanne

UIScrollView CustomStickyHeader Resize height generates problems when scroll is too fast

Angular material date-picker (MatDatepicker) auto completes the date on focus out