(no subject)

Date view Thread view Subject view Author view

From: ATL Oledog (atl_oledog@hotmail.com)
Date: Wed Mar 22 2000 - 06:14:25 PST


Could someone please help? Per a suggestion i put the below line in my
pmfirewall.rules.local but i am still getting about 5 full pages of the
identical security violations from the below 2 ip addresses every 4 hours.
I am running Logcheck so it is emailed to me every four hours and it is
always showing them. This has been going on for the last 8 days. I want to
protect this port but don't want to be unindated with all the excessive
logging.

Thanks guys....

$IPCHAINS -A input -p udp -s $REMOTENET -d $REMOTENET 2031 -i $OUTERIF -j
DENY

Security Violations
=-=-=-=-=-=-=-=-=-=
Mar 22 00:00:18 dti kernel: Packet log: input DENY eth0 PROTO=17
10.0.0.1:2301 255.255.255.255:2301 L=40 S=0x00 I=55740 F=0x0000 T=128 (#28)
Mar 22 00:00:54 dti kernel: Packet log: input DENY eth0 PROTO=17
216.79.140.85:2301 255.255.255.255:2301 L=40 S=0x00 I=61372 F=0x0000 T=128
(#28)
______________________________________________________
Get Your Private, Free Email at http://www.hotmail.com

****************************************************************************
* To UNSUBSCRIBE from the list, send a message with "unsubscribe pmfirewall"
* in the message body to majordomo@pointman.org. Please direct other
* questions, comments, or problems to pmfirewall-owner@pointman.org.


Date view Thread view Subject view Author view

This archive was generated by hypermail 2b29 : Sun Jun 10 2001 - 02:34:11 PDT