We have a test-lab with a FW-1 R54 with four NICs.

On once NIC is a utopia ADSL router with ip x.x.x.99 and on another NIC is a
linux server with ip y.y.y.139. The linux server is running ipchains as a
local firewall.

Today I found the following entry in /var/log/messages:

Packet log: input ACCEPT eth0 PROTO=1 x.x.x..99:3 y.y.y.139:1 L=56 S=0x00
I=7070 F=0x0000 T=254 (#66)

I'm not sure what PROTO=1 is. I know that TCP is PROTO=6. Maybe it is udp?

The problem is that the FireWall-1 between the router and the server does not
have any rules that accept this traffic.

What is going on?

--
J�rn Dahl-Stamnes
E-mail: [EMAIL PROTECTED]
Homepage: http://www.dahl-stamnes.net/dahls/index.php

"Sometime all of our thoughts are misgiven
And it makes me wonder"

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to