|
Hi all,
I'm running redhat 7.2 with kernel
2.4.9-17.
My netfilter is masquerading outgoing traffic
from my internal lan.
This morning, from my win98 station I tried to
access some sites in the internet but I couldn't resolve the names. So I logged
in the firewall and I saw it dropped the answers of my DNS server!! After
some tries it started to function normally. Was netfilter "sleeping" and
suddenly it "woke up"?
It's too strange how could he(the
firewall) drop the answers for himself - his input rules are set to
"-m state --state ESTABLISHED,RELATED -j ACCEPT".
Bellow are the packets that were dropped. My
firewall is 200.X.X.15 and the DNS is 200.X.X.1
Mar 7 08:56:09 skyl kernel: IPT INPUT packet
died: IN=eth0 OUT= MAC=00:02:55
:c0:fd:f1:00:06:29:73:58:a2:08:00 SRC="200.X.X.1" DST=200.X.X.15 LEN=75 TOS= 0x00 PREC=0x00 TTL=64 ID=59824 PROTO=UDP SPT=53 DPT=1040 LEN=55 Mar 7 08:56:32 skyl kernel: IPT INPUT packet died: IN=eth0 OUT= MAC=00:02:55 :c0:fd:f1:00:06:29:73:58:a2:08:00 SRC="200.X.X.1" DST=200.X.X.15 LEN=68 TOS= 0x00 PREC=0x00 TTL=64 ID=60090 PROTO=UDP SPT=53 DPT=1038 LEN=48 Mar 7 08:56:43 skyl kernel: IPT INPUT packet died: IN=eth0 OUT= MAC=00:02:55 :c0:fd:f1:00:06:29:73:58:a2:08:00 SRC="200.X.X.1" DST=200.X.X.15 LEN=72 TOS= 0x00 PREC=0x00 TTL=64 ID=60212 PROTO=UDP SPT=53 DPT=1043 LEN=52 Thank you,
-------------------------------------------------
-- Bruno Negr�o -- Suporte -- Plugway Acesso Internet Ltda. -- (31)34812311 -- [EMAIL PROTECTED] |
- Re: NETFILTER WAS SLEEPING THIS MORNING!! Bruno Negr�o
- Re: NETFILTER WAS SLEEPING THIS MORNING!! Tony Earnshaw
- Re: NETFILTER WAS SLEEPING THIS MORNING!! Bruno Negr�o
