Jim Ford wrote:
Further to my problem:

I've now found that the packets being rejected by the internal network interface on my firewall, are originating from strange ports owned by the Azureus bittorrent client I'm running. The ports in use are as follows:

Ports owned by the Azureus process (as determined by fport):
TCP:1075,1076,1077,1078,1079,1080,1577,1884,1885,1937,1938,1938,1942,1943,1944,
2129,2172,2173,3068,3069,4418,4824,4825,6880,45100

UDP:123,137,138,1025,1071,4453,4454,4455,4500,4670

(I've not listed the port I've allocated to Azureus.)

A lot of these are mighty suspicious, but fortunately none of them are reaching the outside world.

I've still no idea what's happening!

Jim Ford

Any underlying problem here is an Azuerus issue, not a LEAF issue, so you'd do better to look to the Azuerus (or perhaps the BitTorrent) community for help. However, based on your prior report, I don't think you should assume that "none of them are reaching the outside world" ... not without checking, anyway.

Shorewall on LEAF blocks traffic to the external IP address from LAN sources, but it doesn't in general block traffic from arbitrary ports on the LAN to other off-LAN IP addresses (it can't, since that is by and large what your *normal* Internet traffic is). Shorewall doesn't log this ALLOWed traffic, so you might want to find out whether any of it is going out (say by using Ethereal of your LAN host is Windows, or (for example) tcpdump if it is Linux).



-------------------------------------------------------
This SF.Net email is sponsored by xPML, a groundbreaking scripting language
that extends applications into web and mobile media. Attend the live webcast
and join the prime developer group breaking into this new coding territory!
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=110944&bid=241720&dat=121642
------------------------------------------------------------------------
leaf-user mailing list: leaf-user@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/leaf-user
Support Request -- http://leaf-project.org/

Reply via email to