The following is some lines in my messages file logged by ipchains:
May 17 18:47:43 firewall kernel: Packet log: input REJECT eth1 PROTO=6
10.82.43.130:80 202.106.75.97:62290 L=678 S=0x00 I=5553 F=0x4000 T=118
May 17 18:47:43 firewall kernel: Packet log: output ACCEPT eth0 PROTO=1
202.106.75.97:3 10.82.43.130:3 L=576 S=0xC0 I=8673 F=0x0000 T=255
May 17 18:47:43 firewall kernel: Packet log: input REJECT eth1 PROTO=6
10.82.43.130:80 202.106.75.97:62311 L=40 S=0x00 I=5809 F=0x4000 T=118
May 17 18:47:43 firewall kernel: Packet log: output ACCEPT eth0 PROTO=1
202.106.75.97:3 10.82.43.130:3 L=88 S=0xC0 I=8674 F=0x0000 T=255
May 17 18:47:43 firewall kernel: Packet log: input REJECT eth1 PROTO=6
10.82.43.130:80 202.106.75.97:62311 L=44 S=0x00 I=6065 F=0x4000 T=118
May 17 18:47:43 firewall kernel: Packet log: output ACCEPT eth0 PROTO=1
202.106.75.97:3 10.82.43.130:3 L=92 S=0xC0 I=8675 F=0x0000 T=255
eth0 is my internal interface, and eth1 is my external interface, I use ip
masq to let internal machines get out.
I don't know why my external interface capture an 10.82.43.130?
I'm not sure it is an attact. And the output chain let 202.106.75.97:3 ->
10.82.43.130:3 pass, is this a security hole?
I'm very worry about that! Please give a hand.
qiucheng
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]