Weird entries in my firewall
Next message: Joel A. Folkerts: "RE: Computer forensics to uncover illegal internet use"
Date: 30 Aug 2005 15:31:01 -0000
To: security-basics@securityfocus.com
('binary' encoding is not supported, stored as-is)
Hi list,
I've been getting these weird entries in my firewall (iptables) for a while...
BLOCK 12:29:37.371982 OPT1 192.168.0.50, port 2401 255.255.255.255, port 712 UDP
Now, the source is the internal IP of my server, which is not connected to the firewall. It's as if the traffic goes through the external interface using the internal ip, and always broadcasts to port 712. Two of my servers are doing that.
Has anyone ever seen something like this? It has me completely stumped.
Thanks!
Next message: Joel A. Folkerts: "RE: Computer forensics to uncover illegal internet use"
Relevant Pages
- Re: Feedback solicited - best way to harden a mail/web server?
... Was the system protected by a properly configured firewall? ... it's not a bad "starting point" and it can generate an IPtables rule ... > nor is there a web or ftp server; aside from that I haven't tried to secure ... Before I'll install some nifty application ... (comp.os.linux.security) - Re: Confused about bridging, firewall (iptables), and DHCP
... and qemu and CentOS in it are working fine. ... server can't use qemu's default user mode network, ... tun driver, and also past iptables). ... outside the iptables firewall. ... (Fedora) - Re: Confused about bridging, firewall (iptables), and DHCP
... and qemu and CentOS in it are working fine. ... server can't use qemu's default user mode network, ... tun driver, and also past iptables). ... outside the iptables firewall. ... (Fedora) - PPPOE xDSL Firewall with IPTABLES
... don't know how to modify my firewall to account for this. ... Starts and stops the IPTABLES packet filter \ ... # Kill malformed XMAS packets ... # server/client to server query or response ... (comp.os.linux.networking) - Netscreen Malicious URL - how to?
... An example "pretend" firewall entry, ... Those entries do work for both inbound and outbound, ... external proxy server then coming back into our server. ... (comp.security.firewalls) |
|