Re: [Dorset] Firewall question

2023-12-14 Thread Ralph Corderoy
Hi Tim, > > sudo -i ss -p dst 66.39.101.110 > > This did not return anything You need to run it when Wireshark shows traffic of interest, giving the relevant remote IP address. > Is this the expected actions of a Private VPN?? All VPNs are private. :-) It depends what your VPN aims to

Re: [Dorset] Firewall question

2023-12-13 Thread Tim
On 13/12/2023 18:36, Ralph Corderoy wrote: Hi Tim, This was about 12 minutes ago That shows a local TCP port 56946 talking to remote port 80 on 185.151.30.148. I can also talk to that remote port. $ curl -sSvghttp://185.151.30.148; echo * Trying 185.151.30.148:80... *

Re: [Dorset] Firewall question

2023-12-13 Thread Ralph Corderoy
Hi Tim, > This was about 12 minutes ago That shows a local TCP port 56946 talking to remote port 80 on 185.151.30.148. I can also talk to that remote port. $ curl -sSvg http://185.151.30.148; echo * Trying 185.151.30.148:80... * TCP_NODELAY set * Connected to 185.151.30.148

Re: [Dorset] Firewall question

2023-12-13 Thread Tim
On 13/12/2023 17:47, Tim wrote: On 13/12/2023 17:31, Ralph Corderoy wrote: Hi Tim, State: Listen Recv-Q: 0 On all interfaces: Send-Q  Local Peer Process 100 0.0.0.0:smtp    :25   0.0.0.0:* users:(("master",pid=3664,fd=13)) ino:39331

Re: [Dorset] Firewall question

2023-12-13 Thread Tim
On 13/12/2023 17:31, Ralph Corderoy wrote: Hi Tim, State: Listen Recv-Q: 0 On all interfaces: Send-Q Local Peer Process 100 0.0.0.0:smtp:25 0.0.0.0:* users:(("master",pid=3664,fd=13)) ino:39331

Re: [Dorset] Firewall question

2023-12-13 Thread Tim
My message has been blocked as I included an image in the reply Can somebody unblock please. Tim H On 13/12/2023 17:31, Ralph Corderoy wrote: Hi Tim, State: Listen Recv-Q: 0 On all interfaces: Send-Q Local Peer Process 100 0.0.0.0:smtp:25 0.0.0.0:*

Re: [Dorset] Firewall question

2023-12-13 Thread Ralph Corderoy
Hi Tim, > State: Listen > Recv-Q: 0 On all interfaces: > Send-Q Local Peer Process > 100 0.0.0.0:smtp:25 0.0.0.0:* users:(("master",pid=3664,fd=13)) > ino:39331 sk:7 cgroup:/system.slice/system-postfix.slice/postfix@-.service <-> > 100 [::]:smtp :25

Re: [Dorset] Firewall question

2023-12-13 Thread Tim
On 13/12/2023 12:26, Ralph Corderoy wrote: Hi Tim, IP hostnameinout total last seen 98.159.234.100 chrysippo.dreamsinheels.com377,452,876 8,790,117,140 9,167,570,016 2d 18h 38m 35s 98.159.234.101

Re: [Dorset] Firewall question

2023-12-13 Thread Ralph Corderoy
Hi Tim, IP hostnameinout total last seen > 98.159.234.100 chrysippo.dreamsinheels.com377,452,876 8,790,117,140 > 9,167,570,016 2d 18h 38m 35s > 98.159.234.101 reformidans.dreamsinheels.com 231,512,992

Re: [Dorset] Firewall question

2023-12-12 Thread Tim
Hi Ralph Thank for taking a look. On 12/12/2023 12:23, Ralph Corderoy wrote: Hi Tim, Beginning of last week I became aware of a lot of connection to and from .dreamsinheels.com Where are these showing up? I have been using a program called Garkstat (commandline version is darkstat

Re: [Dorset] Firewall question

2023-12-12 Thread Ralph Corderoy
Hi Tim, > Beginning of last week I became aware of a lot of connection to and > from .dreamsinheels.com Where are these showing up? > I have not been able to block the connection, all the sub domains seem > to be coming from 185.151.30.148 ... > Can anybody help with some advise please on how

[Dorset] Firewall question

2023-12-11 Thread Tim
I am running Mint 21.2 XFCE and using the UFW Firewall (using GUFW) as well as a personal VPN to the internet. Beginning of last week I became aware of a lot of connection to and from .dreamsinheels.com (no it is not a dodgy porn site). I use the term some sub domains as I have counted