Package: logcheck-database Version: 1.2.54 Severity: wishlist Typically about twice an hour, I get log entries from Shorewall noticing packets with a source port of 5353 going to port 5353 at 224.0.0.251. As near as I can tell this is ignorable information having to do with appletalk and zeroconf. I think the package on my site that is generating this an avahi related one.
What seems to work for me is an entry of: kernel: Shorewall:.*DST=224\.0\.0\.251.*PROTO=UDP SPT=5353 DPT=5353 Maybe this is of interest to others? Or, maybe I shouldn't be ignoring this? -- System Information: Debian Release: 4.0 APT prefers unstable APT policy: (500, 'unstable'), (500, 'testing') Architecture: i386 (i686) Shell: /bin/sh linked to /bin/bash Kernel: Linux 2.6.16 Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968) Versions of packages logcheck-database depends on: ii debconf [debconf-2.0] 1.5.11 Debian configuration management sy logcheck-database recommends no packages. -- debconf information: * logcheck-database/rules-directories-note: * logcheck-database/standard-rename-note: * logcheck-database/conffile-cleanup: false * logcheck-database/security_level: workstation _______________________________________________ Logcheck-devel mailing list [email protected] http://lists.alioth.debian.org/mailman/listinfo/logcheck-devel

