Re: Interesting firewall log

From: Michael Heiming (
Date: 12/08/02

From: Michael Heiming <>
Date: Sun, 08 Dec 2002 11:32:52 +0100

ynotssor <ynotssor> wrote:

> Michael Heiming wrote:
> [...]
>> Looks like someone scanning for www server/proxy server, not
>> uncommon, but the ipt_unclean looks strange, originates by:
>> /usr/src/linux/net/ipv4/netfilter/ipt_unclean.c
>> If someone has some more insight about what happend, I would be
>> thankfull to hear.
> It's for whatever reason; probably an ECN issue?

Thx, that might be the reason, had to disable it (tcp_ecn) for some
reasons, not long ago. Just strange that someone looks at all those
ports, commonly used for http/http-proxy.

Not applicable, I'm running 2.4.20 and ipt_unclean.c looks like like,
everything and more from this patch, has been build in.


Michael Heiming

Remove +SIGNS, if you expect an answer