/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


> Here is a part of my logfile:
> > Apr 18 20:07:21 server kernel: Packet log: input - eth0 PROTO=17 192.168.10.1:138 
>192.168.10.255:138 L=217 S=0x00 I=482 F=0x0000 T=64 (#1)
> > Apr 18 20:07:23 server kernel: Packet log: input - eth0 PROTO=17 
>192.168.10.20:1135 195.243.188.5:53 L=59 S=0x00 I=23309 F=0x0000 T=32 (#1)
> > Apr 18 20:07:23 server kernel: OPEN: 192.168.10.99 -> 195.243.188.5 UDP, port: 
>61097 -> 53
> > Apr 18 20:07:23 server kernel: ippp0: dialing 1 0215255...
> 
> (192.168.10.x is my LAN
>  192.168.10.20 is one of the Win clients
>  195.243.188.5 is my ISP's nameserver)
> 
> What does the port 1135 usually do? Can I just deny all packets from 
> this port? Why does Windows send these packets? Is there another
> solution?
> 

 It seems that some program is trying to connect to some site on the
Internet. From your log I can see that there is traffic going to port 53
that is DSN queries port on a bind server.

 Maybe you should try tcpdump on your linux box to see to what sites your
clients are connecting to. Your line is going up because of the DNS
queries to that site.

 Do your clients have real player, icq or any other "permanent" state
software installed?

 Regards,
 Raul

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to