Stange rule

From: Charles Flèche (charles.fleche_at_free.fr)
Date: 09/26/04


Date: Sun, 26 Sep 2004 14:03:14 +0200

Hi !
I'm using Linux Mandrake 10.0 Community.
This is my shorewall's rules :

ACCEPT net fw udp 22,111,635,1014,2049,40411 -
ACCEPT net fw tcp 22,111,638,1017,2049,4080,17338,36819 -
ACCEPT loc fw udp 22,111,635,1014,2049,40411 -
ACCEPT loc fw tcp 22,111,638,1017,2049,4080,17338,36819 -

17338 is my custom port for the edonkey network, using mldonkey. Very often,
I'm receiving this kind of message in the netfilter logs :

Sep 26 13:57:25 pingouin kernel: Shorewall:newnotsyn:DROP:IN=eth0 OUT=
MAC=00:d0:70:01:ff:62:00:07:cb:06:1b:a0:08:00 SRC=82.255.55.48
DST=192.168.0.10 LEN=40 TOS=0x00 PREC=0x00 TTL=125 ID=61576 DF PROTO=TCP
SPT=3374 DPT=17338 WINDOW=65535 RES=0x00 ACK FINURGP=0

17338 is opened, so why this packet is dropped ?

Pingouin, my server, is behind a nat with redirection for 22 and 17338 to
him.

Thanx !



Relevant Pages

  • NFS problem with recent 2.6 kernels (also serial console weirdness)
    ... 100000 2 tcp 111 portmapper ... 100000 2 udp 111 portmapper ... mounted filesystem with ordered data mode. ... Mounted root (ext3 filesystem) readonly. ...
    (Linux-Kernel)
  • Solaris 9 <---> linux (2.6.8) NFS file locking problem?
    ... to the same file placed on nfs filesystem. ... 100000 4 tcp 111 portmapper ... 100000 4 udp 111 portmapper ... 100021 1 udp 4045 nlockmgr ...
    (SunManagers)
  • Urgent help with Secure NFS.
    ... have that option - I'm just attempting to tunnel all NFS traffic to the ... 100000 4 tcp 111 rpcbind ... 100000 4 udp 111 rpcbind ... 100021 1 tcp 49153 nlockmgr ...
    (SSH)
  • Re: nfs error
    ... kernel: nfs: server ... So if your system uses ypbind be sure that is working properly before ... 100000 2 tcp 111 portmapper ... 100000 2 udp 111 portmapper ...
    (comp.sys.sun.admin)
  • Re: Incoherent E-mails
    ... The Novell crap was originally run on IPX ... The term in the early-mid nineties was "packet storm". ... The original advantage of UDP was ... > 60 bytes for TCP. ...
    (alt.computer.security)