Re: Is this typical of what fills everybody's logs? -was- Re: [Leaf-user] Hits on port 53.

2001-12-02 Thread Patrick Benson
Leaf Leaf wrote: > No, but In a very cursory look through my recent logs > I have noticed one instance of about 100 packets from > one address denied in a 30 sec period. I'm guessing > it's a scan through my /27 block for some service on > port 27374, sample: > > Nov 28 18:19:43 firewall kernel:

Is this typical of what fills everybody's logs? -was- Re: [Leaf-user] Hits on port 53.

2001-12-02 Thread Leaf Leaf
--- Kevin Kropf <[EMAIL PROTECTED]> wrote: > > Has anybody out their seen the following, hits on > port 53? > Sample: > Dec 1 14:48:57 kc_firewall kernel: Packet log: > input DENY eth0 PROTO=6 > 216.34.68.2:15209 24.80.151.202:53 L=44 S=0x00 I=0 > F=0x T=248 (#44) No, but In a very

RE: [Leaf-user] Hits on port 53.

2001-12-02 Thread Paul Rimmer
> Has anybody out their seen the following, hits on port 53? Yep, this is a well known problem (see archives, when they work...). Change ipfilter_firewall_cfg in ipfilter.conf with these extra lines (#New Port 53 filter start/end): ipfilter_firewall_cfg () { local ADDR local DEST local NET loc

[Leaf-user] Hits on port 53.

2001-12-01 Thread Kevin Kropf
Has anybody out their seen the following, hits on port 53? Their is about 100 entries like this in a few seconds then nothing? This only happens now and again, once or twice a week. I am using EigerStein2BETA.exe. Sample: Dec 1 14:48:57 kc_firewall kernel: Packet log: input DENY eth0 PROTO=