RE: [Leaf-user] Hits on port 53.

2001-12-02 Thread Paul Rimmer
Has anybody out their seen the following, hits on port 53? Yep, this is a well known problem (see archives, when they work...). Change ipfilter_firewall_cfg in ipfilter.conf with these extra lines (#New Port 53 filter start/end): ipfilter_firewall_cfg () { local ADDR local DEST local NET

Is this typical of what fills everybody's logs? -was- Re: [Leaf-user] Hits on port 53.

2001-12-02 Thread Leaf Leaf
--- Kevin Kropf [EMAIL PROTECTED] wrote: Has anybody out their seen the following, hits on port 53? Sample: Dec 1 14:48:57 kc_firewall kernel: Packet log: input DENY eth0 PROTO=6 216.34.68.2:15209 24.80.151.202:53 L=44 S=0x00 I=0 F=0x T=248 (#44) No, but In a very cursory

Re: Is this typical of what fills everybody's logs? -was- Re: [Leaf-user] Hits on port 53.

2001-12-02 Thread Patrick Benson
Leaf Leaf wrote: No, but In a very cursory look through my recent logs I have noticed one instance of about 100 packets from one address denied in a 30 sec period. I'm guessing it's a scan through my /27 block for some service on port 27374, sample: Nov 28 18:19:43 firewall kernel:

[Leaf-user] Hits on port 53.

2001-12-01 Thread Kevin Kropf
Has anybody out their seen the following, hits on port 53? Their is about 100 entries like this in a few seconds then nothing? This only happens now and again, once or twice a week. I am using EigerStein2BETA.exe. Sample: Dec 1 14:48:57 kc_firewall kernel: Packet log: input DENY eth0