Re: [leaf-user] Shorewall log interpretation

2005-12-08 Thread Greg Morgan
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Jim Ford wrote: > Any tips regarding spotting genuine attacks on a Bering UClib box, rather > than 'noise'? Are there any 'dead giveaway' ports or IP addresses? > > Jim Ford Jim, That's hard to answer because the pattern changes over time. What I

[leaf-user] Re: TCP Destination port DPT=2703 Blocked by Bering uClibc 2.3.1

2005-12-08 Thread Kwon
Looks like someone is trying to connect to a Systems Management Server 2003, using your internal ip 192.168.73.76. Look for the heading: Port requirements: SMS Remote Control System service: Wuser32 That’s strange! 192.168.73.76 is a Gentoo Linux email (Postfix) and web (Apache) server. Why wou

[leaf-user] Shorewall log interpretation

2005-12-08 Thread Jim Ford
Any tips regarding spotting genuine attacks on a Bering UClib box, rather than 'noise'? Are there any 'dead giveaway' ports or IP addresses? Jim Ford --- This SF.net email is sponsored by: Splunk Inc. Do you grep through log files for problem

Re: [leaf-user] DNAT rule

2005-12-08 Thread Jim Ford
> Wouldn't it just be easier and more secure to set the machine to a static > IP? > You may need to change the range of static IP addresses - or determine what > it is, but for my money that makes the most sense. I guess so, but I would rather not 'hard wire' anything into the configuration. Bu