blob: 3fc3749ae5257ed1e061f3433d0aee35ca832e25 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
<HEAD>
<TITLE> [Mageia-dev] Decoding iptables message
</TITLE>
<LINK REL="Index" HREF="index.html" >
<LINK REL="made" HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20Decoding%20iptables%20message&In-Reply-To=%3CCA%2BCX%2BbggUp_dGe6Hj-p-QCdT9iYG6A%2B2v4x%2Bw_UgQxZkhuUg6Q%40mail.gmail.com%3E">
<META NAME="robots" CONTENT="index,nofollow">
<META http-equiv="Content-Type" content="text/html; charset=us-ascii">
<LINK REL="Previous" HREF="017130.html">
<LINK REL="Next" HREF="017140.html">
</HEAD>
<BODY BGCOLOR="#ffffff">
<H1>[Mageia-dev] Decoding iptables message</H1>
<B>Pascal Terjan</B>
<A HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20Decoding%20iptables%20message&In-Reply-To=%3CCA%2BCX%2BbggUp_dGe6Hj-p-QCdT9iYG6A%2B2v4x%2Bw_UgQxZkhuUg6Q%40mail.gmail.com%3E"
TITLE="[Mageia-dev] Decoding iptables message">pterjan at gmail.com
</A><BR>
<I>Wed Jul 4 16:42:41 CEST 2012</I>
<P><UL>
<LI>Previous message: <A HREF="017130.html">[Mageia-dev] Decoding iptables message
</A></li>
<LI>Next message: <A HREF="017140.html">[Mageia-dev] Decoding iptables message
</A></li>
<LI> <B>Messages sorted by:</B>
<a href="date.html#17137">[ date ]</a>
<a href="thread.html#17137">[ thread ]</a>
<a href="subject.html#17137">[ subject ]</a>
<a href="author.html#17137">[ author ]</a>
</LI>
</UL>
<HR>
<!--beginarticle-->
<PRE>On Wed, Jul 4, 2012 at 4:07 AM, Anne Wilson <<A HREF="https://www.mageia.org/mailman/listinfo/mageia-dev">annew at kde.org</A>> wrote:
><i> -----BEGIN PGP SIGNED MESSAGE-----
</I>><i> Hash: SHA1
</I>><i>
</I>><i> Could someone please tell me what to look for, and where, to solve
</I>><i> this puzzle?
</I>
Where do this message come from? I have never seen any such messages
for iptables drops.
><i> - --------------------- iptables firewall Begin ------------------------
</I>><i>
</I>><i>
</I>><i> Listed by source hosts:
</I>><i> Dropped 9 packets on interface eth0
</I>><i> From 192.168.0.40 - 9 packets to tcp(38575)
</I>><i>
</I>><i> ---------------------- iptables firewall End -------------------------
</I>><i>
</I>><i> The machine in question is my mail/file/print server, running a
</I>><i> secondary firewall inside the NAT router. Port 38575 appears to be
</I>><i> unassigned, and I've only seen such messages for the last couple of days.
</I>
Which machine in question? The one displaying this message or 192.168.0.40?
><i> I'm pretty sure that the server hasn't been _directly_ used, i.e. with
</I>><i> login to actual physical box, during that time, so the likelihood
</I>><i> seems to be some service other systems on the LAN are calling for
</I>><i> something.
</I>><i>
</I>><i> Any ideas about how to go about tracing this? I can't find it in any
</I>><i> of the logs on the server. I'm working on the logs on the laptops.
</I></PRE>
<!--endarticle-->
<HR>
<P><UL>
<!--threads-->
<LI>Previous message: <A HREF="017130.html">[Mageia-dev] Decoding iptables message
</A></li>
<LI>Next message: <A HREF="017140.html">[Mageia-dev] Decoding iptables message
</A></li>
<LI> <B>Messages sorted by:</B>
<a href="date.html#17137">[ date ]</a>
<a href="thread.html#17137">[ thread ]</a>
<a href="subject.html#17137">[ subject ]</a>
<a href="author.html#17137">[ author ]</a>
</LI>
</UL>
<hr>
<a href="https://www.mageia.org/mailman/listinfo/mageia-dev">More information about the Mageia-dev
mailing list</a><br>
</body></html>
|