Is the 10.82.43.130 address from your internal network, and the
202... on the external side?
> From: "qiu cheng" <[EMAIL PROTECTED]>
> To: [EMAIL PROTECTED]
> Subject: [Masq] security alarm
> Date: Wed, 19 May 1999 04:46:36 PDT
>
> The following is some lines in my messages file logged by ipchains:
>
> May 17 18:47:43 firewall kernel: Packet log: input REJECT eth1 PROTO=6
> 10.82.43.130:80 202.106.75.97:62290 L=678 S=0x00 I=5553 F=0x4000 T=118
> May 17 18:47:43 firewall kernel: Packet log: output ACCEPT eth0 PROTO=1
> 202.106.75.97:3 10.82.43.130:3 L=576 S=0xC0 I=8673 F=0x0000 T=255
> May 17 18:47:43 firewall kernel: Packet log: input REJECT eth1 PROTO=6
> 10.82.43.130:80 202.106.75.97:62311 L=40 S=0x00 I=5809 F=0x4000 T=118
> May 17 18:47:43 firewall kernel: Packet log: output ACCEPT eth0 PROTO=1
> 202.106.75.97:3 10.82.43.130:3 L=88 S=0xC0 I=8674 F=0x0000 T=255
> May 17 18:47:43 firewall kernel: Packet log: input REJECT eth1 PROTO=6
> 10.82.43.130:80 202.106.75.97:62311 L=44 S=0x00 I=6065 F=0x4000 T=118
> May 17 18:47:43 firewall kernel: Packet log: output ACCEPT eth0 PROTO=1
> 202.106.75.97:3 10.82.43.130:3 L=92 S=0xC0 I=8675 F=0x0000 T=255
>
> eth0 is my internal interface, and eth1 is my external interface, I use ip
> masq to let internal machines get out.
>
> I don't know why my external interface capture an 10.82.43.130?
> I'm not sure it is an attact. And the output chain let 202.106.75.97:3 ->
> 10.82.43.130:3 pass, is this a security hole?
>
> I'm very worry about that! Please give a hand.
>
> qiucheng
>
>
>
>
> _______________________________________________
> Masq maillist - [EMAIL PROTECTED]
> http://tiffany.indyramp.com/mailman/listinfo/masq
> Admin requests can be handled by web (above) or [EMAIL PROTECTED]
>
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]