Ask the Community
Groups
Ubiquiti - Connect IT Community | Kaseya
<main> <article class="userContent"> <h2 data-id="review-configuration-options-for-ubiquiti-firewalls-in-rocketcyber">Review configuration options for Ubiquiti firewalls in RocketCyber</h2> <table border="1" cellpadding="4"><tbody><tr><td>IP blacklisted by OpenProxies </td> <td rowspan="3">These are IP addresses that have been labelled as malicious by different threat intelligence sources</td> </tr><tr><td>IP blacklisted by OpenBL</td> </tr><tr><td>IP blacklisted by ASL</td> </tr><tr><td>Emerging threats</td> <td>Checks traffic against known malicious actors</td> </tr><tr><td>Suspicious origin IP</td> <td>Checks for traffic originating from regions with high proportions of malicious actors (e.g. Iran)</td> </tr><tr><td>DDoS attack via NTP</td> <td rowspan="2">These are different means of attempting to bring down your network by overwhelming available resources</td> </tr><tr><td>DDoS attack via DNS amplifier</td> </tr><tr><td>Heartbleed attack</td> <td>Checks for attempts to exploit the Heartbleed vulnerability, which would allow an attacker to access whatever data is in active memory on the machine</td> </tr></tbody></table><h3 data-id="log-format">Log Format</h3> <p>The expected format for Ubiquiti logs is <strong>space-separated</strong>. For example</p> <p><4>May 19 11:57:51 UBG-Dallas kernel: [WAN_IN-3005-A]IN=eth2 OUT=eth0 MAC=18:e8:29:aa:aa:aa:aa:aa:aa:aa:aa:aa:aa:00 SRC=96.78.75.73 DST=70.70.71.75 LEN=52 TOS=0x02 PREC=0x00 TTL=111 ID=9777 DF PROTO=TCP SPT=56777 DPT=8777 WINDOW=8192 RES=0x00 CWR ECE SYN URGP=0</p> </article> </main>