On 21/08/2011 17:44, Tom Eastep wrote:
> Ed -- I specifically asked that the dump be forwarded as an attachment.
> Placing it inline has caused your mailer to fold it until it is unreadable.
Apologies you did indeed. Mailing lists are a tricky fine line to
tread. I have recently been posting to the kernel mailing list using
using my mailer (thunderbird on osx) and as a result it defaults to
plain text, no attachments... (I wish we could just all agree that html
email is ok...)
Correctly attached this time I believe... Note, I have recreated the
dump - I have scanned it by eye and I believe it shows the same
representative dump as before - obviously the previous dump still
available for correlation
Apologies - thanks for looking into this
Ed W
Shorewall 4.4.22.3 Dump at localhost - Sun Aug 21 22:30:21 UTC 2011
Counters reset Sun Aug 21 16:28:28 UTC 2011
Chain INPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
1127 89120 accountin all -- * * 0.0.0.0/0 0.0.0.0/0
1127 89120 dynamic all -- * * 0.0.0.0/0 0.0.0.0/0
ctstate INVALID,NEW
954 83584 net2fw all -- eth0 * 0.0.0.0/0 0.0.0.0/0
0 0 net2fw all -- ppp1 * 0.0.0.0/0 0.0.0.0/0
173 5536 loc2fw all -- br0 * 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
0 0 Reject all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0
LOG flags 0 level 6 prefix "Shorewall:INPUT:REJECT:"
0 0 reject all -- * * 0.0.0.0/0 0.0.0.0/0
[goto]
Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 accountfwd all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 net_frwd all -- eth0 * 0.0.0.0/0 0.0.0.0/0
0 0 net_frwd all -- ppp1 * 0.0.0.0/0 0.0.0.0/0
0 0 loc_frwd all -- br0 * 0.0.0.0/0 0.0.0.0/0
0 0 Reject all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0
LOG flags 0 level 6 prefix "Shorewall:FORWARD:REJECT:"
0 0 reject all -- * * 0.0.0.0/0 0.0.0.0/0
[goto]
Chain OUTPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
373 28476 accountout all -- * * 0.0.0.0/0 0.0.0.0/0
373 28476 fw2net all -- * eth0 0.0.0.0/0 0.0.0.0/0
0 0 fw2net all -- * ppp1 0.0.0.0/0 0.0.0.0/0
0 0 fw2loc all -- * br0 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- * lo 0.0.0.0/0 0.0.0.0/0
0 0 Reject all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0
LOG flags 0 level 6 prefix "Shorewall:OUTPUT:REJECT:"
0 0 reject all -- * * 0.0.0.0/0 0.0.0.0/0
[goto]
Chain Broadcast (2 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
ADDRTYPE match dst-type BROADCAST
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
ADDRTYPE match dst-type MULTICAST
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
ADDRTYPE match dst-type ANYCAST
0 0 DROP all -- * * 0.0.0.0/0 224.0.0.0/4
Chain Drop (3 references)
pkts bytes target prot opt in out source destination
0 0 all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 reject tcp -- * * 0.0.0.0/0 0.0.0.0/0
tcp dpt:113 /* Auth */
0 0 Broadcast all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0
icmptype 3 code 4 /* Needed ICMP types */
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0
icmptype 11 /* Needed ICMP types */
0 0 Invalid all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0
multiport dports 135,445 /* SMB */
0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0
udp dpts:137:139 /* SMB */
0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0
udp spt:137 dpts:1024:65535 /* SMB */
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0
multiport dports 135,139,445 /* SMB */
0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0
udp dpt:1900 /* UPnP */
0 0 NotSyn tcp -- * * 0.0.0.0/0 0.0.0.0/0
0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0
udp spt:53 /* Late DNS Replies */
Chain Invalid (2 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
ctstate INVALID
Chain NotSyn (2 references)
pkts bytes target prot opt in out source destination
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0
tcpflags:! 0x17/0x02
Chain Reject (6 references)
pkts bytes target prot opt in out source destination
0 0 all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 reject tcp -- * * 0.0.0.0/0 0.0.0.0/0
tcp dpt:113 /* Auth */
0 0 Broadcast all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0
icmptype 3 code 4 /* Needed ICMP types */
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0
icmptype 11 /* Needed ICMP types */
0 0 Invalid all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 reject udp -- * * 0.0.0.0/0 0.0.0.0/0
multiport dports 135,445 /* SMB */
0 0 reject udp -- * * 0.0.0.0/0 0.0.0.0/0
udp dpts:137:139 /* SMB */
0 0 reject udp -- * * 0.0.0.0/0 0.0.0.0/0
udp spt:137 dpts:1024:65535 /* SMB */
0 0 reject tcp -- * * 0.0.0.0/0 0.0.0.0/0
multiport dports 135,139,445 /* SMB */
0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0
udp dpt:1900 /* UPnP */
0 0 NotSyn tcp -- * * 0.0.0.0/0 0.0.0.0/0
0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0
udp spt:53 /* Late DNS Replies */
Chain accountfwd (1 references)
pkts bytes target prot opt in out source destination
0 0 ACCOUNT all -- * * 0.0.0.0/0 0.0.0.0/0
ACCOUNT addr 192.168.111.0/24 tname net-loc
0 0 all -- ppp1 * 0.0.0.0/0 0.0.0.0/0
0 0 all -- * ppp1 0.0.0.0/0 0.0.0.0/0
0 0 all -- eth0 * 0.0.0.0/0 0.0.0.0/0
0 0 all -- * eth0 0.0.0.0/0 0.0.0.0/0
0 0 udp -- eth0 * 0.0.0.0/0 0.0.0.0/0
0 0 udp -- * eth0 0.0.0.0/0 0.0.0.0/0
0 0 icmp -- eth0 * 0.0.0.0/0 0.0.0.0/0
0 0 icmp -- * eth0 0.0.0.0/0 0.0.0.0/0
Chain accountin (1 references)
pkts bytes target prot opt in out source destination
0 0 all -- ppp1 * 0.0.0.0/0 0.0.0.0/0
954 83584 all -- eth0 * 0.0.0.0/0 0.0.0.0/0
Chain accountout (1 references)
pkts bytes target prot opt in out source destination
373 28476 ACCOUNT all -- * * 0.0.0.0/0 0.0.0.0/0
ACCOUNT addr 192.168.111.0/24 tname net-loc
0 0 all -- * ppp1 0.0.0.0/0 0.0.0.0/0
373 28476 all -- * eth0 0.0.0.0/0 0.0.0.0/0
Chain dynamic (7 references)
pkts bytes target prot opt in out source destination
Chain fw2loc (1 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
ctstate RELATED,ESTABLISHED
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0
LOG flags 0 level 6 prefix "Shorewall:fw2loc:LOG:"
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0
LOG flags 0 level 6 prefix "Shorewall:fw2loc:LOG:"
0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 Reject all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0
LOG flags 0 level 6 prefix "Shorewall:fw2loc:REJECT:"
0 0 reject all -- * * 0.0.0.0/0 0.0.0.0/0
[goto]
Chain fw2net (2 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
ctstate RELATED,ESTABLISHED
373 28476 LOG all -- * * 0.0.0.0/0 0.0.0.0/0
LOG flags 0 level 6 prefix "Shorewall:fw2net:LOG:"
373 28476 LOG all -- * * 0.0.0.0/0 0.0.0.0/0
LOG flags 0 level 6 prefix "Shorewall:fw2net:LOG:"
373 28476 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 Reject all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0
LOG flags 0 level 6 prefix "Shorewall:fw2net:REJECT:"
0 0 reject all -- * * 0.0.0.0/0 0.0.0.0/0
[goto]
Chain loc2fw (1 references)
pkts bytes target prot opt in out source destination
173 5536 dynamic all -- * * 0.0.0.0/0 0.0.0.0/0
ctstate INVALID,NEW
173 5536 smurfs all -- * * 0.0.0.0/0 0.0.0.0/0
ctstate INVALID,NEW
0 0 tcpflags tcp -- * * 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
ctstate RELATED,ESTABLISHED
173 5536 LOG all -- * * 0.0.0.0/0 0.0.0.0/0
LOG flags 0 level 6 prefix "Shorewall:loc2fw:LOG:"
173 5536 LOG all -- * * 0.0.0.0/0 0.0.0.0/0
LOG flags 0 level 6 prefix "Shorewall:loc2fw:LOG:"
173 5536 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 Reject all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0
LOG flags 0 level 6 prefix "Shorewall:loc2fw:REJECT:"
0 0 reject all -- * * 0.0.0.0/0 0.0.0.0/0
[goto]
Chain loc2net (2 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
ctstate RELATED,ESTABLISHED
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0
LOG flags 0 level 6 prefix "Shorewall:loc2net:LOG:"
0 0 Drop all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0
LOG flags 0 level 6 prefix "Shorewall:loc2net:DROP:"
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
Chain loc_frwd (1 references)
pkts bytes target prot opt in out source destination
0 0 dynamic all -- * * 0.0.0.0/0 0.0.0.0/0
ctstate INVALID,NEW
0 0 smurfs all -- * * 0.0.0.0/0 0.0.0.0/0
ctstate INVALID,NEW
0 0 tcpflags tcp -- * * 0.0.0.0/0 0.0.0.0/0
0 0 loc2net all -- * eth0 0.0.0.0/0 0.0.0.0/0
0 0 loc2net all -- * ppp1 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- * br0 0.0.0.0/0 0.0.0.0/0
Chain logdrop (0 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
Chain logflags (5 references)
pkts bytes target prot opt in out source destination
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0
LOG flags 4 level 6 prefix "Shorewall:logflags:DROP:"
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
Chain logreject (0 references)
pkts bytes target prot opt in out source destination
0 0 reject all -- * * 0.0.0.0/0 0.0.0.0/0
Chain net2fw (2 references)
pkts bytes target prot opt in out source destination
954 83584 dynamic all -- * * 0.0.0.0/0 0.0.0.0/0
ctstate INVALID,NEW
954 83584 dynamic all -- * * 0.0.0.0/0 0.0.0.0/0
ctstate INVALID,NEW
0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
ctstate RELATED,ESTABLISHED
954 83584 LOG all -- * * 0.0.0.0/0 0.0.0.0/0
LOG flags 0 level 6 prefix "Shorewall:net2fw:LOG:"
954 83584 LOG all -- * * 0.0.0.0/0 0.0.0.0/0
LOG flags 0 level 6 prefix "Shorewall:net2fw:LOG:"
954 83584 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 Drop all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0
LOG flags 0 level 6 prefix "Shorewall:net2fw:DROP:"
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
Chain net2loc (1 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
ctstate RELATED,ESTABLISHED
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0
LOG flags 0 level 6 prefix "Shorewall:net2loc:LOG:"
0 0 Drop all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0
LOG flags 0 level 6 prefix "Shorewall:net2loc:DROP:"
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
Chain net_frwd (2 references)
pkts bytes target prot opt in out source destination
0 0 sfilter all -- * eth0 0.0.0.0/0 0.0.0.0/0
[goto]
0 0 dynamic all -- * * 0.0.0.0/0 0.0.0.0/0
ctstate INVALID,NEW
0 0 sfilter all -- * ppp1 0.0.0.0/0 0.0.0.0/0
[goto]
0 0 dynamic all -- * * 0.0.0.0/0 0.0.0.0/0
ctstate INVALID,NEW
0 0 ACCEPT all -- * eth0 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- * ppp1 0.0.0.0/0 0.0.0.0/0
0 0 net2loc all -- * br0 0.0.0.0/0 0.0.0.0/0
Chain reject (13 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
ADDRTYPE match src-type BROADCAST
0 0 DROP all -- * * 224.0.0.0/4 0.0.0.0/0
0 0 DROP 2 -- * * 0.0.0.0/0 0.0.0.0/0
0 0 REJECT tcp -- * * 0.0.0.0/0 0.0.0.0/0
reject-with tcp-reset
0 0 REJECT udp -- * * 0.0.0.0/0 0.0.0.0/0
reject-with icmp-port-unreachable
0 0 REJECT icmp -- * * 0.0.0.0/0 0.0.0.0/0
reject-with icmp-host-unreachable
0 0 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0
reject-with icmp-host-prohibited
Chain sfilter (2 references)
pkts bytes target prot opt in out source destination
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0
LOG flags 0 level 6 prefix "Shorewall:sfilter:DROP:"
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
Chain shorewall (0 references)
pkts bytes target prot opt in out source destination
Chain smurflog (2 references)
pkts bytes target prot opt in out source destination
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0
LOG flags 0 level 6 prefix "Shorewall:smurfs:DROP:"
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
Chain smurfs (2 references)
pkts bytes target prot opt in out source destination
173 5536 RETURN all -- * * 0.0.0.0 0.0.0.0/0
0 0 smurflog all -- * * 0.0.0.0/0 0.0.0.0/0
[goto] ADDRTYPE match src-type BROADCAST
0 0 smurflog all -- * * 224.0.0.0/4 0.0.0.0/0
[goto]
Chain tcpflags (2 references)
pkts bytes target prot opt in out source destination
0 0 logflags tcp -- * * 0.0.0.0/0 0.0.0.0/0
[goto] tcpflags: 0x3F/0x29
0 0 logflags tcp -- * * 0.0.0.0/0 0.0.0.0/0
[goto] tcpflags: 0x3F/0x00
0 0 logflags tcp -- * * 0.0.0.0/0 0.0.0.0/0
[goto] tcpflags: 0x06/0x06
0 0 logflags tcp -- * * 0.0.0.0/0 0.0.0.0/0
[goto] tcpflags: 0x03/0x03
0 0 logflags tcp -- * * 0.0.0.0/0 0.0.0.0/0
[goto] tcp spt:0flags: 0x17/0x02
Log (/var/log/messages)
Aug 21 22:29:35 localhost kern.info Shorewall:net2fw:LOG:IN=eth0 OUT=
SRC=192.168.105.7 DST=255.255.255.255 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF
PROTO=UDP SPT=3483 DPT=3483 LEN=24 MARK=0x10000
Aug 21 22:29:35 localhost kern.info Shorewall:net2fw:LOG:IN=eth0 OUT=
SRC=192.168.105.7 DST=255.255.255.255 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF
PROTO=UDP SPT=3483 DPT=3483 LEN=24 MARK=0x10000
Aug 21 22:29:58 localhost kern.info Shorewall:fw2net:LOG:IN= OUT=eth0
SRC=192.168.105.70 DST=91.220.24.240 LEN=76 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF
PROTO=UDP SPT=123 DPT=123 LEN=56 MARK=0xc0000
Aug 21 22:29:58 localhost kern.info Shorewall:fw2net:LOG:IN= OUT=eth0
SRC=192.168.105.70 DST=91.220.24.240 LEN=76 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF
PROTO=UDP SPT=123 DPT=123 LEN=56 MARK=0xc0000
Aug 21 22:30:08 localhost kern.info Shorewall:loc2fw:LOG:IN=br0 OUT=
SRC=0.0.0.0 DST=224.0.0.1 LEN=32 TOS=0x00 PREC=0xC0 TTL=1 ID=0 DF PROTO=2
MARK=0x10000
Aug 21 22:30:08 localhost kern.info Shorewall:loc2fw:LOG:IN=br0 OUT=
SRC=0.0.0.0 DST=224.0.0.1 LEN=32 TOS=0x00 PREC=0xC0 TTL=1 ID=0 DF PROTO=2
MARK=0x10000
Aug 21 22:30:15 localhost kern.info Shorewall:fw2net:LOG:IN= OUT=eth0
SRC=192.168.105.70 DST=91.220.24.20 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF
PROTO=ICMP TYPE=8 CODE=0 ID=46691 SEQ=0 MARK=0xc0000
Aug 21 22:30:15 localhost kern.info Shorewall:fw2net:LOG:IN= OUT=eth0
SRC=192.168.105.70 DST=91.220.24.20 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF
PROTO=ICMP TYPE=8 CODE=0 ID=46691 SEQ=0 MARK=0xc0000
Aug 21 22:30:16 localhost kern.info Shorewall:fw2net:LOG:IN= OUT=eth0
SRC=192.168.105.70 DST=91.220.24.20 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF
PROTO=ICMP TYPE=8 CODE=0 ID=46691 SEQ=1 MARK=0xc0000
Aug 21 22:30:16 localhost kern.info Shorewall:fw2net:LOG:IN= OUT=eth0
SRC=192.168.105.70 DST=91.220.24.20 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF
PROTO=ICMP TYPE=8 CODE=0 ID=46691 SEQ=1 MARK=0xc0000
Aug 21 22:30:17 localhost kern.info Shorewall:fw2net:LOG:IN= OUT=eth0
SRC=192.168.105.70 DST=91.220.24.20 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF
PROTO=ICMP TYPE=8 CODE=0 ID=46691 SEQ=2 MARK=0xc0000
Aug 21 22:30:17 localhost kern.info Shorewall:fw2net:LOG:IN= OUT=eth0
SRC=192.168.105.70 DST=91.220.24.20 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF
PROTO=ICMP TYPE=8 CODE=0 ID=46691 SEQ=2 MARK=0xc0000
Aug 21 22:30:18 localhost kern.info Shorewall:fw2net:LOG:IN= OUT=eth0
SRC=192.168.105.70 DST=91.220.24.20 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF
PROTO=ICMP TYPE=8 CODE=0 ID=46691 SEQ=3 MARK=0xc0000
Aug 21 22:30:18 localhost kern.info Shorewall:fw2net:LOG:IN= OUT=eth0
SRC=192.168.105.70 DST=91.220.24.20 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF
PROTO=ICMP TYPE=8 CODE=0 ID=46691 SEQ=3 MARK=0xc0000
Aug 21 22:30:19 localhost kern.info Shorewall:fw2net:LOG:IN= OUT=eth0
SRC=192.168.105.70 DST=91.220.24.20 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF
PROTO=ICMP TYPE=8 CODE=0 ID=46691 SEQ=4 MARK=0xc0000
Aug 21 22:30:19 localhost kern.info Shorewall:fw2net:LOG:IN= OUT=eth0
SRC=192.168.105.70 DST=91.220.24.20 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF
PROTO=ICMP TYPE=8 CODE=0 ID=46691 SEQ=4 MARK=0xc0000
NAT Table
Chain PREROUTING (policy ACCEPT 1 packets, 44 bytes)
pkts bytes target prot opt in out source destination
Chain INPUT (policy ACCEPT 1 packets, 44 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy ACCEPT 2 packets, 160 bytes)
pkts bytes target prot opt in out source destination
Chain POSTROUTING (policy ACCEPT 2 packets, 160 bytes)
pkts bytes target prot opt in out source destination
0 0 eth0_masq all -- * eth0 0.0.0.0/0 0.0.0.0/0
359 27300 ppp1_masq all -- * ppp1 0.0.0.0/0 0.0.0.0/0
Chain eth0_masq (1 references)
pkts bytes target prot opt in out source destination
0 0 MASQUERADE all -- * * 192.168.111.0/24 0.0.0.0/0
Chain ppp1_masq (1 references)
pkts bytes target prot opt in out source destination
0 0 MASQUERADE all -- * * 192.168.111.0/24 0.0.0.0/0
Mangle Table
Chain PREROUTING (policy ACCEPT 2 packets, 76 bytes)
pkts bytes target prot opt in out source destination
353 27726 CONNMARK all -- * * 0.0.0.0/0 0.0.0.0/0
connmark match ! 0x0/0xff0000 CONNMARK restore mask 0xff0000
774 61394 routemark all -- eth0 * 0.0.0.0/0 0.0.0.0/0
mark match 0x0/0xff0000
0 0 routemark all -- ppp1 * 0.0.0.0/0 0.0.0.0/0
mark match 0x0/0xff0000
1127 89120 tcpre all -- * * 0.0.0.0/0 0.0.0.0/0
Chain INPUT (policy ACCEPT 2 packets, 76 bytes)
pkts bytes target prot opt in out source destination
1127 89120 tcin all -- * * 0.0.0.0/0 0.0.0.0/0
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 tcfor all -- * * 0.0.0.0/0 0.0.0.0/0
Chain OUTPUT (policy ACCEPT 6 packets, 496 bytes)
pkts bytes target prot opt in out source destination
0 0 CONNMARK all -- * * 0.0.0.0/0 0.0.0.0/0
connmark match ! 0x0/0xff0000 CONNMARK restore mask 0xff0000
373 28476 tcout all -- * * 0.0.0.0/0 0.0.0.0/0
Chain POSTROUTING (policy ACCEPT 6 packets, 496 bytes)
pkts bytes target prot opt in out source destination
373 28476 tcpost all -- * * 0.0.0.0/0 0.0.0.0/0
Chain routemark (2 references)
pkts bytes target prot opt in out source destination
774 61394 MARK all -- eth0 * 0.0.0.0/0 0.0.0.0/0
MARK set 0x10000
0 0 MARK all -- ppp1 * 0.0.0.0/0 0.0.0.0/0
MARK set 0xc0000
774 61394 CONNMARK all -- * * 0.0.0.0/0 0.0.0.0/0
mark match ! 0x0/0xff0000 CONNMARK save mask 0xff0000
Chain tcfor (1 references)
pkts bytes target prot opt in out source destination
Chain tcin (1 references)
pkts bytes target prot opt in out source destination
Chain tcout (1 references)
pkts bytes target prot opt in out source destination
373 28476 MARK all -- * * 0.0.0.0/0 0.0.0.0/0
MARK set 0xc0000
Chain tcpost (1 references)
pkts bytes target prot opt in out source destination
Chain tcpre (1 references)
pkts bytes target prot opt in out source destination
Raw Table
Chain PREROUTING (policy ACCEPT 1127 packets, 89120 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy ACCEPT 373 packets, 28476 bytes)
pkts bytes target prot opt in out source destination
Conntrack Table (3 out of 14864)
icmp 1 27 src=192.168.105.70 dst=91.220.24.20 type=8 code=0 id=46691
packets=5 bytes=420 [UNREPLIED] src=91.220.24.20 dst=192.168.105.70 type=0
code=0 id=46691 packets=0 bytes=0 mark=0 use=2
unknown 2 586 src=0.0.0.0 dst=224.0.0.1 packets=1316 bytes=42112 [UNREPLIED]
src=224.0.0.1 dst=0.0.0.0 packets=0 bytes=0 mark=65536 use=2
udp 17 7 src=192.168.105.70 dst=91.220.24.240 sport=123 dport=123
packets=1 bytes=76 [UNREPLIED] src=91.220.24.240 dst=192.168.105.70 sport=123
dport=123 packets=0 bytes=0 mark=0 use=2
IP Configuration
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 16436 qdisc noqueue state UNKNOWN
inet 127.0.0.1/8 scope host lo
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state
UNKNOWN qlen 1000
inet 192.168.105.70/24 brd 192.168.105.255 scope global eth0
12: br0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UNKNOWN
inet 192.168.111.254/24 brd 192.168.111.255 scope global br0
15: ppp1: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast
state UNKNOWN qlen 3
inet 10.49.134.86 peer 10.64.64.65/32 scope global ppp1
IP Stats
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 16436 qdisc noqueue state UNKNOWN
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
RX: bytes packets errors dropped overrun mcast
196068 2108 0 0 0 0
TX: bytes packets errors dropped carrier collsns
196068 2108 0 0 0 0
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state
UNKNOWN qlen 1000
link/ether 00:0d:b9:13:49:b4 brd ff:ff:ff:ff:ff:ff
RX: bytes packets errors dropped overrun mcast
2204475 33778 0 1650 0 0
TX: bytes packets errors dropped carrier collsns
84944 831 0 0 0 0
3: eth1: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc pfifo_fast state
DOWN qlen 1000
link/ether 00:0d:b9:13:49:b5 brd ff:ff:ff:ff:ff:ff
RX: bytes packets errors dropped overrun mcast
0 0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
0 0 0 0 0 0
4: eth2: <NO-CARRIER,BROADCAST,MULTICAST,PROMISC,UP> mtu 1500 qdisc pfifo_fast
state DOWN qlen 1000
link/ether 00:0d:b9:13:49:b6 brd ff:ff:ff:ff:ff:ff
RX: bytes packets errors dropped overrun mcast
0 0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
0 0 0 0 0 0
5: dummy0: <BROADCAST,NOARP> mtu 1500 qdisc noop state DOWN
link/ether 3e:cf:69:a4:61:dc brd ff:ff:ff:ff:ff:ff
RX: bytes packets errors dropped overrun mcast
0 0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
0 0 0 0 0 0
6: teql0: <NOARP> mtu 1500 qdisc noop state DOWN qlen 100
link/void
RX: bytes packets errors dropped overrun mcast
0 0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
0 0 0 0 0 0
7: tunl0: <NOARP> mtu 1480 qdisc noop state DOWN
link/ipip 0.0.0.0 brd 0.0.0.0
RX: bytes packets errors dropped overrun mcast
0 0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
0 0 0 0 0 0
8: sit0: <NOARP> mtu 1480 qdisc noop state DOWN
link/sit 0.0.0.0 brd 0.0.0.0
RX: bytes packets errors dropped overrun mcast
0 0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
0 0 0 0 0 0
9: ip6tnl0: <NOARP> mtu 1452 qdisc noop state DOWN
link/tunnel6 :: brd ::
RX: bytes packets errors dropped overrun mcast
0 0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
0 0 0 0 0 0
10: wlan0: <BROADCAST,MULTICAST> mtu 1500 qdisc mq state DOWN qlen 1000
link/ether 00:80:48:54:c0:ac brd ff:ff:ff:ff:ff:ff
RX: bytes packets errors dropped overrun mcast
1499 11 0 0 0 0
TX: bytes packets errors dropped carrier collsns
95504 1136 0 0 0 0
11: wlan1: <BROADCAST,MULTICAST> mtu 1500 qdisc mq state DOWN qlen 1000
link/ether 00:1f:1f:cb:d0:e2 brd ff:ff:ff:ff:ff:ff
RX: bytes packets errors dropped overrun mcast
2392650 7401 0 219 0 0
TX: bytes packets errors dropped carrier collsns
259353 2773 0 0 0 0
12: br0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UNKNOWN
link/ether 00:0d:b9:13:49:b6 brd ff:ff:ff:ff:ff:ff
RX: bytes packets errors dropped overrun mcast
1363 14 0 0 0 0
TX: bytes packets errors dropped carrier collsns
65054 757 0 0 0 0
15: ppp1: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast
state UNKNOWN qlen 3
link/ppp
RX: bytes packets errors dropped overrun mcast
4760 65 0 0 0 0
TX: bytes packets errors dropped carrier collsns
61173 792 0 0 0 0
Bridges
bridge name bridge id STP enabled interfaces
br0 8000.000db91349b6 no eth2
Per-IP Counters
Showing table: net-loc
/proc
/proc/version = Linux version 2.6.38.4-aufs-grsec-ipset (root@quad) (gcc
version 4.4.5 (Gentoo Hardened 4.4.5 p1.2, pie-0.4.5) ) #11 Mon Aug 15 21:40:28
BST 2011
/proc/sys/net/ipv4/ip_forward = 1
/proc/sys/net/ipv4/icmp_echo_ignore_all = 0
/proc/sys/net/ipv4/conf/all/proxy_arp = 0
/proc/sys/net/ipv4/conf/all/arp_filter = 0
/proc/sys/net/ipv4/conf/all/arp_ignore = 0
/proc/sys/net/ipv4/conf/all/rp_filter = 0
/proc/sys/net/ipv4/conf/all/log_martians = 0
/proc/sys/net/ipv4/conf/br0/proxy_arp = 0
/proc/sys/net/ipv4/conf/br0/arp_filter = 0
/proc/sys/net/ipv4/conf/br0/arp_ignore = 0
/proc/sys/net/ipv4/conf/br0/rp_filter = 0
/proc/sys/net/ipv4/conf/br0/log_martians = 1
/proc/sys/net/ipv4/conf/default/proxy_arp = 0
/proc/sys/net/ipv4/conf/default/arp_filter = 0
/proc/sys/net/ipv4/conf/default/arp_ignore = 0
/proc/sys/net/ipv4/conf/default/rp_filter = 0
/proc/sys/net/ipv4/conf/default/log_martians = 1
/proc/sys/net/ipv4/conf/dummy0/proxy_arp = 0
/proc/sys/net/ipv4/conf/dummy0/arp_filter = 0
/proc/sys/net/ipv4/conf/dummy0/arp_ignore = 0
/proc/sys/net/ipv4/conf/dummy0/rp_filter = 0
/proc/sys/net/ipv4/conf/dummy0/log_martians = 1
/proc/sys/net/ipv4/conf/eth0/proxy_arp = 0
/proc/sys/net/ipv4/conf/eth0/arp_filter = 0
/proc/sys/net/ipv4/conf/eth0/arp_ignore = 0
/proc/sys/net/ipv4/conf/eth0/rp_filter = 0
/proc/sys/net/ipv4/conf/eth0/log_martians = 1
/proc/sys/net/ipv4/conf/eth1/proxy_arp = 0
/proc/sys/net/ipv4/conf/eth1/arp_filter = 0
/proc/sys/net/ipv4/conf/eth1/arp_ignore = 0
/proc/sys/net/ipv4/conf/eth1/rp_filter = 0
/proc/sys/net/ipv4/conf/eth1/log_martians = 1
/proc/sys/net/ipv4/conf/eth2/proxy_arp = 0
/proc/sys/net/ipv4/conf/eth2/arp_filter = 0
/proc/sys/net/ipv4/conf/eth2/arp_ignore = 0
/proc/sys/net/ipv4/conf/eth2/rp_filter = 0
/proc/sys/net/ipv4/conf/eth2/log_martians = 1
/proc/sys/net/ipv4/conf/ip6tnl0/proxy_arp = 0
/proc/sys/net/ipv4/conf/ip6tnl0/arp_filter = 0
/proc/sys/net/ipv4/conf/ip6tnl0/arp_ignore = 0
/proc/sys/net/ipv4/conf/ip6tnl0/rp_filter = 0
/proc/sys/net/ipv4/conf/ip6tnl0/log_martians = 1
/proc/sys/net/ipv4/conf/lo/proxy_arp = 0
/proc/sys/net/ipv4/conf/lo/arp_filter = 0
/proc/sys/net/ipv4/conf/lo/arp_ignore = 0
/proc/sys/net/ipv4/conf/lo/rp_filter = 0
/proc/sys/net/ipv4/conf/lo/log_martians = 1
/proc/sys/net/ipv4/conf/ppp1/proxy_arp = 0
/proc/sys/net/ipv4/conf/ppp1/arp_filter = 0
/proc/sys/net/ipv4/conf/ppp1/arp_ignore = 0
/proc/sys/net/ipv4/conf/ppp1/rp_filter = 0
/proc/sys/net/ipv4/conf/ppp1/log_martians = 1
/proc/sys/net/ipv4/conf/sit0/proxy_arp = 0
/proc/sys/net/ipv4/conf/sit0/arp_filter = 0
/proc/sys/net/ipv4/conf/sit0/arp_ignore = 0
/proc/sys/net/ipv4/conf/sit0/rp_filter = 0
/proc/sys/net/ipv4/conf/sit0/log_martians = 1
/proc/sys/net/ipv4/conf/teql0/proxy_arp = 0
/proc/sys/net/ipv4/conf/teql0/arp_filter = 0
/proc/sys/net/ipv4/conf/teql0/arp_ignore = 0
/proc/sys/net/ipv4/conf/teql0/rp_filter = 0
/proc/sys/net/ipv4/conf/teql0/log_martians = 1
/proc/sys/net/ipv4/conf/tunl0/proxy_arp = 0
/proc/sys/net/ipv4/conf/tunl0/arp_filter = 0
/proc/sys/net/ipv4/conf/tunl0/arp_ignore = 0
/proc/sys/net/ipv4/conf/tunl0/rp_filter = 0
/proc/sys/net/ipv4/conf/tunl0/log_martians = 1
/proc/sys/net/ipv4/conf/wlan0/proxy_arp = 0
/proc/sys/net/ipv4/conf/wlan0/arp_filter = 0
/proc/sys/net/ipv4/conf/wlan0/arp_ignore = 0
/proc/sys/net/ipv4/conf/wlan0/rp_filter = 0
/proc/sys/net/ipv4/conf/wlan0/log_martians = 1
/proc/sys/net/ipv4/conf/wlan1/proxy_arp = 0
/proc/sys/net/ipv4/conf/wlan1/arp_filter = 0
/proc/sys/net/ipv4/conf/wlan1/arp_ignore = 0
/proc/sys/net/ipv4/conf/wlan1/rp_filter = 0
/proc/sys/net/ipv4/conf/wlan1/log_martians = 1
Routing Rules
0: from all lookup local
10000: from all fwmark 0x10000/0xff0000 lookup peth0
10011: from all fwmark 0xc0000/0xff0000 lookup pppp1
20000: from 192.168.105.70 lookup peth0
22816: from 10.49.134.86 lookup pppp1
32766: from all lookup main
32767: from all lookup default
Table default:
Table local:
local 10.49.134.86 dev ppp1 proto kernel scope host src 10.49.134.86
broadcast 127.255.255.255 dev lo proto kernel scope link src 127.0.0.1
broadcast 192.168.111.0 dev br0 proto kernel scope link src 192.168.111.254
broadcast 192.168.111.255 dev br0 proto kernel scope link src
192.168.111.254
broadcast 192.168.105.0 dev eth0 proto kernel scope link src 192.168.105.70
broadcast 192.168.105.255 dev eth0 proto kernel scope link src
192.168.105.70
local 192.168.111.254 dev br0 proto kernel scope host src 192.168.111.254
broadcast 127.0.0.0 dev lo proto kernel scope link src 127.0.0.1
local 192.168.105.70 dev eth0 proto kernel scope host src 192.168.105.70
local 127.0.0.1 dev lo proto kernel scope host src 127.0.0.1
local 127.0.0.0/8 dev lo proto kernel scope host src 127.0.0.1
Table main:
192.168.105.1 dev eth0 scope link src 192.168.105.70
10.64.64.65 dev ppp1 proto kernel scope link src 10.49.134.86
192.168.111.0/24 dev br0 proto kernel scope link src 192.168.111.254
192.168.105.0/24 dev eth0 proto kernel scope link src 192.168.105.70 metric
2
127.0.0.0/8 via 127.0.0.1 dev lo
default via 192.168.105.1 dev eth0 metric 2
default via 10.64.64.65 dev ppp1 metric 450
Table peth0:
192.168.105.1 dev eth0 scope link src 192.168.105.70
192.168.111.0/24 dev br0 proto kernel scope link src 192.168.111.254
192.168.105.0/24 dev eth0 proto kernel scope link src 192.168.105.70 metric
2
default via 192.168.105.1 dev eth0 src 192.168.105.70
Table pppp1:
10.64.64.65 dev ppp1 proto kernel scope link src 10.49.134.86
192.168.111.0/24 dev br0 proto kernel scope link src 192.168.111.254
default dev ppp1 scope link
ARP
? (192.168.105.1) at 00:1b:63:f4:15:8c [ether] on eth0
Modules
ip_set 14689 3 ip_set_hash_ip,xt_set,ip_set_bitmap_ipmac
ip_set_bitmap_ipmac 3872 7
ip_set_hash_ip 12856 0
xt_ACCOUNT 8220 2
xt_IPMARK 695 0
xt_LOGMARK 1352 0
xt_set 2707 0
Shorewall has detected the following iptables/netfilter capabilities:
NAT: Available
Packet Mangling: Available
Multi-port Match: Available
Extended Multi-port Match: Available
Connection Tracking Match: Available
Extended Connection Tracking Match Support: Available
Packet Type Match: Available
Policy Match: Available
Physdev Match: Available
Physdev-is-bridged Support: Available
Packet length Match: Available
IP range Match: Available
Recent Match: Available
Owner Match: Available
Ipset Match: Available
CONNMARK Target: Available
Extended CONNMARK Target: Available
Connmark Match: Available
Extended Connmark Match: Available
Raw Table: Available
IPP2P Match: Not available
CLASSIFY Target: Available
Extended REJECT: Available
Repeat match: Available
MARK Target: Available
Extended MARK Target: Available
Extended MARK Target 2: Available
Mangle FORWARD Chain: Available
Comments: Available
Address Type Match: Available
TCPMSS Match: Available
Hashlimit Match: Available
NFQUEUE Target: Available
Realm Match: Available
Helper Match: Available
Connlimit Match: Available
Time Match: Available
Goto Support: Available
LOGMARK Target: Available
IPMARK Target: Available
LOG Target: Available
Persistent SNAT: Available
TPROXY Target: Available
FLOW Classifier: Available
fwmark route mask: Available
Mark in any table: Available
Header Match: Not available
ACCOUNT Target: Available
AUDIT Target: Not available
ipset V5: Available
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address Foreign Address State
PID/Program name
tcp 0 0 0.0.0.0:53 0.0.0.0:* LISTEN
21262/dnsmasq
tcp 0 0 :::53 :::* LISTEN
21262/dnsmasq
tcp 0 0 :::22 :::* LISTEN
10183/dropbear
udp 0 0 0.0.0.0:53 0.0.0.0:*
21262/dnsmasq
udp 0 0 0.0.0.0:67 0.0.0.0:*
21262/dnsmasq
udp 0 0 0.0.0.0:323 0.0.0.0:*
3143/chronyd
udp 0 0 0.0.0.0:123 0.0.0.0:*
3143/chronyd
udp 0 0 :::53 :::*
21262/dnsmasq
udp 0 0 :::323 :::*
3143/chronyd
udp 0 0 :::123 :::*
3143/chronyd
Traffic Control
Device eth0:
qdisc pfifo_fast 0: root refcnt 2 bands 3 priomap 1 2 2 2 1 2 0 0 1 1 1 1 1 1
1 1
Sent 84944 bytes 831 pkt (dropped 0, overlimits 0 requeues 0)
backlog 0b 0p requeues 0
Device eth1:
qdisc pfifo_fast 0: root refcnt 2 bands 3 priomap 1 2 2 2 1 2 0 0 1 1 1 1 1 1
1 1
Sent 0 bytes 0 pkt (dropped 0, overlimits 0 requeues 0)
backlog 0b 0p requeues 0
Device eth2:
qdisc pfifo_fast 0: root refcnt 2 bands 3 priomap 1 2 2 2 1 2 0 0 1 1 1 1 1 1
1 1
Sent 0 bytes 0 pkt (dropped 0, overlimits 0 requeues 0)
backlog 0b 0p requeues 0
Device wlan0:
qdisc mq 0: root
Sent 75056 bytes 1136 pkt (dropped 0, overlimits 0 requeues 0)
backlog 0b 0p requeues 0
class mq :1 root
Sent 0 bytes 0 pkt (dropped 0, overlimits 0 requeues 0)
backlog 0b 0p requeues 0
class mq :2 root
Sent 0 bytes 0 pkt (dropped 0, overlimits 0 requeues 0)
backlog 0b 0p requeues 0
class mq :3 root
Sent 75056 bytes 1136 pkt (dropped 0, overlimits 0 requeues 0)
backlog 0b 0p requeues 0
class mq :4 root
Sent 0 bytes 0 pkt (dropped 0, overlimits 0 requeues 0)
backlog 0b 0p requeues 0
Device wlan1:
qdisc mq 0: root
Sent 203971 bytes 2774 pkt (dropped 0, overlimits 0 requeues 5)
backlog 0b 0p requeues 5
class mq :1 root
Sent 708 bytes 3 pkt (dropped 0, overlimits 0 requeues 0)
backlog 0b 0p requeues 0
class mq :2 root
Sent 0 bytes 0 pkt (dropped 0, overlimits 0 requeues 0)
backlog 0b 0p requeues 0
class mq :3 root
Sent 203263 bytes 2771 pkt (dropped 0, overlimits 0 requeues 5)
backlog 0b 0p requeues 5
class mq :4 root
Sent 0 bytes 0 pkt (dropped 0, overlimits 0 requeues 0)
backlog 0b 0p requeues 0
Device ppp1:
qdisc pfifo_fast 0: root refcnt 2 bands 3 priomap 1 2 2 2 1 2 0 0 1 1 1 1 1 1
1 1
Sent 61083 bytes 786 pkt (dropped 0, overlimits 0 requeues 0)
backlog 0b 0p requeues 0
TC Filters
Device eth0:
Device eth1:
Device eth2:
Device wlan0:
Device wlan1:
Device ppp1:
------------------------------------------------------------------------------
Get a FREE DOWNLOAD! and learn more about uberSVN rich system,
user administration capabilities and model configuration. Take
the hassle out of deploying and managing Subversion and the
tools developers use with it. http://p.sf.net/sfu/wandisco-d2d-2
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users