On Mon, Dec 17, 2001 at 07:10:22PM -0000, Kees Blokland <[EMAIL PROTECTED]> wrote:
> [...]
> Also, to complete the picture.. It's only trying to send 'SYNC' packets..
> That surely smells very suspicious..
> [...]

Do you mean packets with the 'SYN' flag set? The rule only blocks those, 
since you shouldn't get ones without the 'SYN' flag if the 'SYN' packets 
have already been dropped (and you should drop them if you do...)

So, you're only going to see logs of 'SYN' packets.

Gordon
--
  Gordon Rowell                        [EMAIL PROTECTED]
  VP Engineering
  Network Server Solutions Group       http://www.e-smith.com
  Mitel Networks Corporation           http://www.mitel.com


--
Please report bugs to [EMAIL PROTECTED]
Please mail [EMAIL PROTECTED] (only) to discuss security issues
Support for registered customers and partners to [EMAIL PROTECTED]
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]
Archives by mail and http://www.mail-archive.com/devinfo%40lists.e-smith.org

Reply via email to