OPNsense Forum

English Forums => Intrusion Detection and Prevention => Topic started by: LouieLouie on August 31, 2019, 03:41:49 PM

Title: System log entry involves a reported abuse IP, how to investigate?
Post by: LouieLouie on August 31, 2019, 03:41:49 PM
Aug 31 09:28:37    /update_tables.py: error fetching alias url 81.22.45.80

Disclaimer:  To call myself an amateur with security is an insult to the amateurs. 

I'm curious about this log entry.  I googled update_tables.py, the responses were effectively in sanskrit to me.  I know that it's probably a python script, that's it.

Why would opnsense try to fetch an alias for that ip address?  Is this an attack?  Should I do something?

Thank you for your time and consideration.

Title: Re: System log entry involves a reported abuse IP, how to investigate?
Post by: dp on January 13, 2020, 10:05:31 PM
Are you using spamhaus? This IP is on their list as a bad actor and there may have been a hiccup somewhere in the process of updating the table of IPs from their database. To use spamhaus it is setup as an alias.

And it is entirely possible I have no clue of what I am talking about and this is complete gibberish.