UDP connection attempts

看板FB_security作者時間19年前 (2006/07/19 16:24), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/6 (看更多)
Hi everyone, I administer this 5.2.1 Freebsd Box which runs a few services, among of which are bind and postfix. On the same box I run ipfw as a firewall, and have a default policy block for all incoming packets, except for those that are for ports 53 (tcp and udp) and 25 (tcp). I also have the following sysctl values enabled: net.inet.tcp.blackhole=2 net.inet.udp.blackhole=1 In my security logs I keep on getting the following messages: Jul 19 03:04:49 ns1 kernel: Connection attempt to UDP 127.0.0.1:512 from 127.0.0.1:52291 Jul 19 03:25:56 ns1 kernel: Connection attempt to UDP myexternaladdress:52299 from myexternaladdress:53 Jul 19 09:33:11 ns1 kernel: Connection attempt to UDP myexternaladdress:52316 from myexternaladdress:53 Jul 19 10:28:32 ns1 kernel: Connection attempt to UDP 127.0.0.1:512 from 127.0.0.1:52328 Jul 19 11:05:49 ns1 kernel: Connection attempt to UDP 127.0.0.1:512 from 127.0.0.1:52354 I have googled these messages many times, but haven't still found a real explanation of why these messages occur. The way I see it is that there is no malicious behaviour behind theses messages, most probably there's something that has to do with my firewall settings, and the keep state option. I present the excerpt from my firewall configuration file that relates to the dns incoming traffic: add 00389 allow udp from any to myexternaladdress 53 in via fxp0 keep-state I would be greatful if someone could explain to me why these messages keep showing, and if there is a way to prevent them from occuring in the future. Thank you all in advance, mamalos _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #14lUmj00 (FB_security)
文章代碼(AID): #14lUmj00 (FB_security)