[Shorewall-users] long MAC entries in the logs?

Tom Eastep teastep at shorewall.net
Tue Dec 2 11:09:05 PST 2003

On Tue, 2003-12-02 at 09:08, Faxbox wrote:
> I am getting entries like this in my log:
> Dec  2 12:00:42 malakili Shorewall:net2fw:ACCEPT: IN=ppp0 OUT=  
> MAC=c0:29:c0:00:00:00:00:11:00:00:00:00:00:00:00:00:00:00:00:01:00:00:00 
> :00:00:00:00:30:18:00:00:00:00:00:00:01:15:00:00:30:18:00:00:00:00:00:00 
> :00:20:10:c1:00:20:10:c1:00:00:00:00:00:00:00:00:00:00:00:00:a8:40:7e:c1 
> :a8:40:7e:c1:00:00:00:00:80:45:00:00:3c:47:a9:40:00:38:06:63:da:42:cf:c7 
> :22:40:e7:4c:60:f7:14:03:78:92:08:9e:a8:00:00:00:00:a0:02:80:00:54:d0:00 
> :00:02:04:05:ac:01:03:03:00:01:01:08:0a:f2:a8:c1:1f:00:00:00:00:40:7e:c1 
> :00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00 
> :00:00:00:00:00:00:00:00:00  SRC= DST= LEN=60  
> TOS=00 PREC=0x00 TTL=56 ID=18345 DF PROTO=TCP SPT=63252 DPT=888  
> SEQ=2450038440 ACK=0 WINDOW=32768 SYN URGP=0
> What's with the huge MAC address?  This seems to have started when I  
> switched to using ulogd (version 1.02).  Shorewall is version 1.4.7c  
> (from Debian package), BTW.

That's clearly a bug (and not a Shorewall bug) -- I suggest searching
the netfilter mailing list archives as I'm sure that I saw this problem
mentioned there. 

Tom Eastep    \ Nothing is foolproof to a sufficiently talented fool
Shoreline,     \ http://shorewall.net
Washington USA  \ teastep at shorewall.net

More information about the Shorewall-users mailing list