From: Charles Flèche (charles.fleche_at_free.fr)
Date: Sun, 26 Sep 2004 14:03:14 +0200
I'm using Linux Mandrake 10.0 Community.
This is my shorewall's rules :
ACCEPT net fw udp 22,111,635,1014,2049,40411 -
ACCEPT net fw tcp 22,111,638,1017,2049,4080,17338,36819 -
ACCEPT loc fw udp 22,111,635,1014,2049,40411 -
ACCEPT loc fw tcp 22,111,638,1017,2049,4080,17338,36819 -
17338 is my custom port for the edonkey network, using mldonkey. Very often,
I'm receiving this kind of message in the netfilter logs :
Sep 26 13:57:25 pingouin kernel: Shorewall:newnotsyn:DROP:IN=eth0 OUT=
DST=192.168.0.10 LEN=40 TOS=0x00 PREC=0x00 TTL=125 ID=61576 DF PROTO=TCP
SPT=3374 DPT=17338 WINDOW=65535 RES=0x00 ACK FINURGP=0
17338 is opened, so why this packet is dropped ?
Pingouin, my server, is behind a nat with redirection for 22 and 17338 to