/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */



Gary S. MacKay <[EMAIL PROTECTED]> wrote:
>
> I periodically get a slew of these messages in my log files.  Is this
> something I should be worried about or am I blocking something I need?

Let's break this one entry down:

> Jul 15 23:06:08 server kernel: Packet log: output REJECT ppp0 PROTO=6
    207.87.221.241:64071 199.29.68.71:119 L=46 S=0x00 I=24326 F=0x4000 T=127

The "Packet log" tells us that it was logged by an "ipchains" rule which
had the "-l" flag set.

Which rule is not clear, but we know that it was one of the "output"
rules.

The packet in question was REJECT-ed.

The packet was traversing the "ppp0" interface.

The protocol was TCP (TCP = 6, UDP = 17, ICMP = 1).

The source address of the packet was 207.87.221.241, on port 64071.
This is probably the public IP of your server, since the packet has been
masqueraded, so you don't know which of your clients behind the masq box
was responsible for the source packet, without checking the masq table.

The destination address of the packet was 199.29.68.71, port 119.  Some
sort of mail server, and port 119 is the NNTP port.  Someone is trying
to connect to a news server, and your firewall has stopped them from
doing so.

    L=46 S=0x00 I=24326 F=0x4000 T=127

This information is the packet length, service type, ICMP id, packet
flags, and TTL (hop count) for the packet.  They are quite unimportant.

-- 
   [EMAIL PROTECTED] (Fuzzy Fox)      || "Nothing takes the taste out of peanut
sometimes known as David DeSimone  ||  butter quite like unrequited love."
  http://www.dallas.net/~fox/      ||                       -- Charlie Brown



_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/

Reply via email to