[Shorewall-users] Dropped packet question....

Bear bear@amberorder.com
Wed, 2 Jan 2002 05:50:40 -0800


Hi guys, thought maybe someone would know this off the top of their heads=
=2E..

What are seemingly legitimate hosts (this one resolves to AskJeeves) doin=
g
trying to UDP to port 0?  And always with a SPT of 53?

There aren't too many of these in the logs, so it doesn't seem like DNS, =
and
the connection list shows no connections to the related address.

Log entry:
Jan  2 03:27:56 net2all:DROP:IN=3Deth0 OUT=3Deth1 SRC=3D65.214.36.7
DST=3D192.168.0.25 LEN=3D64 TOS=3D0x00 PREC=3D0x00 TTL=3D1 ID=3D32523 PRO=
TO=3DUDP SPT=3D53
DPT=3D0 LEN=3D44

Thanks,
John Stroud
Someday I'll make a real sig


Tracking #: 732ABD26745089459CD8710713632B03567A6149

_______________________________________________
Shorewall-users mailing list
Shorewall-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/shorewall-users