Yes, i've got some BAD state messages.

Some of them:
Jun 24 22:19:55 firewall /bsd: pf: BAD state: TCP 212.123.18.196:80 212.123.18.196:80 
213.224.186.172:4004 [lo=2075491983 high=2075524103 win=1 modulator=0] [lo=133175873 
high=133175874 win=32120 modulator=0] 4:2 PA seq=133175544 ack=2075491983 len=329 
ackskew=0 pkts=3 dir=out,rev
Jun 24 22:19:55 firewall /bsd: pf: State failure on:   2     |
Jun 24 22:20:13 firewall /bsd: pf: BAD state: TCP 212.123.18.196:80 212.123.18.196:80 
195.121.108.230:1084 [lo=1264167 high=1296863 win=1 modulator=0] [lo=95522102 
high=95522103 win=32696 modulator=0] 4:2 PA seq=95521566 ack=1264167 len=536 ackskew=0 
pkts=3 dir=out,rev
Jun 24 22:20:13 firewall /bsd: pf: State failure on:   2     |
Jun 24 22:20:14 firewall /bsd: pf: BAD state: TCP 212.123.18.196:80 212.123.18.196:80 
213.224.186.172:4008 [lo=2075925515 high=2075957635 win=1 modulator=0] [lo=135511219 
high=135511220 win=32120 modulator=0] 4:2 PA seq=135509759 ack=2075925515 len=1460 
ackskew=0 pkts=3 dir=out,rev
Jun 24 22:20:14 firewall /bsd: pf: State failure on:   2     |
Jun 24 22:21:03 firewall /bsd: pf: loose state match: TCP 212.123.18.198:22 
212.123.18.198:22 212.123.18.204:1589 [lo=25371953 high=25371974 win=62892 
modulator=0] [lo=0 high=1 win=1 modulator=0] 2:0 PA seq=25371973 ack=0 len=20 
ackskew=0 pkts=1
Jun 24 22:21:03 firewall /bsd: pf: BAD ICMP state: TCP 212.123.18.198:22 
212.123.18.198:22 212.123.18.204:1589 [lo=25371993 high=25371974 win=62892 
modulator=0] [lo=0 high=62892 win=1 modulator=0] 2:0 seq=3661740033
Jun 24 22:21:05 firewall /bsd: pf: BAD ICMP state: TCP 212.123.18.198:22 
212.123.18.198:22 212.123.18.204:1724 [lo=806265261 high=806265282 win=64240 
modulator=0] [lo=0 high=1 win=1 modulator=0] 2:0 seq=2638353390
Jun 24 22:36:25 firewall /bsd: pf: BAD state: TCP 212.123.18.197:25 212.123.18.197:25 
65.115.124.196:58780 [lo=3395466587 high=3395492999 win=64240 modulator=0] 
[lo=3998489268 high=3998553353 win=32120 modulator=0] 10:10 RA seq=1474607059 
ack=3998489268 len=3 ackskew=0 pkts=29 dir=in,fwd

Sorry, i've replied my own mail. I wasn't subscribed anymore.
 

--
Kenny Gryp
http://gryp.dakin.be

Linux.be:                               http://www.linux.be
Anti Micro$oft Action Front:            http://www.amaf.be
Linux Usergroup West-Vlaanderen:        http://www.lugwv.be
College Linux User Group Torhout:       http://www.c-lugt.be

Attachment: pgp00000.pgp
Description: PGP signature

Reply via email to