Iptables....

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hello!

            My firewall has a rule that protects against new connections without the syn flag. I am logging this rejected packets.

 

            I am observing lots of these packets being dropped, with origin in one my servers. The Origin port is 80. I am also listening on port 80 on this machine (Apache). Are these connection attempts being made by apache, or can them be originated by a different program? If it is Apache, what is the reason?

 

            Jan 27 20:07:00 firewall kernel: Firewall LOG-IN=eth1 OUT=eth0 SRC="" DST=XXX.XXX.XXX.XXX LEN=468 TOS=0x00 PREC=0x00 TTL=63 ID=15690 DF PROTO=TCP SPT=80 DPT=11723 WINDOW=31740 RES=0x00 ACK PSH URGP=0

 

 

            I am using DNAT. The packets which are addressed to DNATed machines pass through the INPUT->OUTPUT chains, right? Or do they pass by the FORWARD chain?

 

            Thanks in advance,

                        Victor Batista


[Index of Archives]     [Fedora Announce]     [Linux Crypto]     [Kernel]     [Netfilter]     [Bugtraq]     [USB]     [Fedora Security]

  Powered by Linux