gropiuskalle
Guru
Tach!
Ich habe hier neuerdings tonnenweise Meldungen in meinen logs, die ich nicht so richtig deuten kann. Hier mal ein Ausschnitt:
Neue Einträge erscheinen alle paar Sekunden. Meine Firewall-Einstellungen sehen so aus:
In diesem Zusammenhang steht vielleicht, dass ich meine Firewall heute aus irgendwelchen rätselhaften Gründen down vorfand und deshalb neu startete. Hat jemand einen Tipp für mich?
Ich habe hier neuerdings tonnenweise Meldungen in meinen logs, die ich nicht so richtig deuten kann. Hier mal ein Ausschnitt:
Code:
6 TOS=0x00 PREC=0x00 TTL=118 ID=9715 DF PROTO=TCP SPT=57409 DPT=4662 WINDOW=8192 RES=0x00 SYN URGP=0 OPT (020405AC0402080A001A797100000000)
[ 8597.027714] SFW2-INext-DROP-DEFLT IN=dsl0 OUT= MAC= SRC=89.131.110.185 DST=85.179.43.136 LEN=91 TOS=0x00 PREC=0x00 TTL=117 ID=55630 PROTO=ICMP TYPE=3 CODE=3 [SRC=85.179.43.136 DST=192.168.2.100 LEN=63 TOS=0x00 PREC=0x00 TTL=50 ID=0 DF PROTO=UDP SPT=65325 DPT=60072 LEN=43 ]
[ 8602.601254] SFW2-INext-DROP-DEFLT IN=dsl0 OUT= MAC= SRC=187.90.188.249 DST=85.179.43.136 LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=1311 DF PROTO=TCP SPT=2875 DPT=6881 WINDOW=16384 RES=0x00 SYN URGP=0 OPT (020405B401010402)
[ 8603.125202] SFW2-INext-DROP-DEFLT IN=dsl0 OUT= MAC= SRC=83.10.196.92 DST=85.179.43.136 LEN=129 TOS=0x00 PREC=0x00 TTL=118 ID=13844 PROTO=UDP SPT=24747 DPT=6881 LEN=109
[ 8611.632500] SFW2-INext-DROP-DEFLT IN=dsl0 OUT= MAC= SRC=187.90.188.249 DST=85.179.43.136 LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=2347 DF PROTO=TCP SPT=2875 DPT=6881 WINDOW=16384 RES=0x00 SYN URGP=0 OPT (020405B401010402)
[ 8620.969761] SFW2-INext-DROP-DEFLT IN=dsl0 OUT= MAC= SRC=59.92.161.165 DST=85.179.43.136 LEN=95 TOS=0x00 PREC=0x00 TTL=118 ID=19203 PROTO=UDP SPT=34551 DPT=6881 LEN=75
[ 8632.500811] SFW2-INext-DROP-DEFLT IN=dsl0 OUT= MAC= SRC=189.15.108.0 DST=85.179.43.136 LEN=60 TOS=0x00 PREC=0x00 TTL=54 ID=49707 DF PROTO=TCP SPT=42533 DPT=6881 WINDOW=5840 RES=0x00 SYN URGP=0 OPT (020405140402080A00FC68C60000000001030305)
[ 8639.142285] SFW2-INext-DROP-DEFLT IN=dsl0 OUT= MAC= SRC=119.237.58.90 DST=85.179.43.136 LEN=129 TOS=0x00 PREC=0x00 TTL=117 ID=13747 PROTO=UDP SPT=9466 DPT=6881 LEN=109
[ 8647.442303] npviewer.bin[11220]: segfault at ff99cd48 ip ff99cd48 sp bffe660c error 14
[ 8653.099131] SFW2-INext-DROP-DEFLT IN=dsl0 OUT= MAC= SRC=67.173.57.58 DST=85.179.43.136 LEN=48 TOS=0x00 PREC=0x00 TTL=117 ID=5465 DF PROTO=TCP SPT=2757 DPT=6881 WINDOW=65535 RES=0x00 SYN URGP=0 OPT (020405B401010402)
[ 8659.090656] SFW2-INext-DROP-DEFLT IN=dsl0 OUT= MAC= SRC=213.191.15.133 DST=85.179.43.136 LEN=129 TOS=0x00 PREC=0x00 TTL=117 ID=30339 PROTO=UDP SPT=7913 DPT=6881 LEN=109
[ 8670.967689] SFW2-INext-DROP-DEFLT IN=dsl0 OUT= MAC= SRC=91.97.0.68 DST=85.179.43.136 LEN=48 TOS=0x00 PREC=0x00 TTL=120 ID=17584 DF PROTO=TCP SPT=62542 DPT=6881 WINDOW=8192 RES=0x00 SYN URGP=0 OPT (0204057801010402)
[ 8679.097063] SFW2-INext-DROP-DEFLT IN=dsl0 OUT= MAC= SRC=203.138.29.227 DST=85.179.43.136 LEN=129 TOS=0x00 PREC=0x00 TTL=113 ID=26642 PROTO=UDP SPT=61924 DPT=6881 LEN=109
[ 8698.971854] SFW2-INext-DROP-DEFLT IN=dsl0 OUT= MAC= SRC=79.117.60.156 DST=85.179.43.136 LEN=52 TOS=0x00 PREC=0x00 TTL=121 ID=24809 DF PROTO=TCP SPT=3146 DPT=6881 WINDOW=65535 RES=0x00 SYN URGP=0 OPT (020405480103030301010402)
[ 8699.113884] SFW2-INext-DROP-DEFLT IN=dsl0 OUT= MAC= SRC=83.240.1.142 DST=85.179.43.136 LEN=95 TOS=0x00 PREC=0x00 TTL=117 ID=48442 PROTO=UDP SPT=25883 DPT=6881 LEN=75
[ 8712.239973] SFW2-INext-DROP-DEFLT IN=dsl0 OUT= MAC= SRC=89.238.168.9 DST=85.179.43.136 LEN=60 TOS=0x00 PREC=0x00 TTL=58 ID=48123 DF PROTO=TCP SPT=15134 DPT=60208 WINDOW=5840 RES=0x00 SYN URGP=0 OPT (020405B40402080A83E31D4D0000000001030307)
[ 8718.568993] SFW2-INext-DROP-DEFLT IN=dsl0 OUT= MAC= SRC=123.185.247.136 DST=85.179.43.136 LEN=129 TOS=0x00 PREC=0x00 TTL=114 ID=4657 PROTO=UDP SPT=7982 DPT=6881 LEN=109
[ 8740.714529] SFW2-INext-DROP-DEFLT IN=dsl0 OUT= MAC= SRC=151.32.227.70 DST=85.179.43.136 LEN=129 TOS=0x00 PREC=0x00 TTL=118 ID=23059 PROTO=UDP SPT=18996 DPT=6881 LEN=109
[ 8743.977020] SFW2-INext-DROP-DEFLT IN=dsl0 OUT= MAC= SRC=70.55.142.4 DST=85.179.43.136 LEN=48 TOS=0x00 PREC=0x00 TTL=118 ID=28263 DF PROTO=TCP SPT=4308 DPT=6881 WINDOW=65535 RES=0x00 SYN URGP=0 OPT (020405AC01010402)
Neue Einträge erscheinen alle paar Sekunden. Meine Firewall-Einstellungen sehen so aus:
Code:
hoppers:~ # iptables-save
# Generated by iptables-save v1.4.4 on Fri Nov 27 16:41:29 2009
*raw
:PREROUTING ACCEPT [575972:80555441]
:OUTPUT ACCEPT [643228:207629276]
-A PREROUTING -i lo -j NOTRACK
-A OUTPUT -o lo -j NOTRACK
COMMIT
# Completed on Fri Nov 27 16:41:29 2009
# Generated by iptables-save v1.4.4 on Fri Nov 27 16:41:29 2009
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [332:26900]
:forward_ext - [0:0]
:input_ext - [0:0]
:reject_func - [0:0]
-A INPUT -i lo -j ACCEPT
-A INPUT -m state --state ESTABLISHED -j ACCEPT
-A INPUT -p icmp -m state --state RELATED -j ACCEPT
-A INPUT -i dsl0 -j input_ext
-A INPUT -i eth0 -j input_ext
-A INPUT -i vboxnet0 -j input_ext
-A INPUT -j input_ext
-A INPUT -m limit --limit 3/min -j LOG --log-prefix "SFW2-IN-ILL-TARGET " --log-tcp-options --log-ip-options
-A INPUT -j DROP
-A FORWARD -m limit --limit 3/min -j LOG --log-prefix "SFW2-FWD-ILL-ROUTING " --log-tcp-options --log-ip-options
-A OUTPUT -o lo -j ACCEPT
-A OUTPUT -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT -m limit --limit 3/min -j LOG --log-prefix "SFW2-OUT-ERROR " --log-tcp-options --log-ip-options
-A input_ext -m pkttype --pkt-type broadcast -j DROP
-A input_ext -p icmp -m icmp --icmp-type 4 -j ACCEPT
-A input_ext -p icmp -m icmp --icmp-type 8 -j ACCEPT
-A input_ext -p tcp -m limit --limit 3/min -m tcp --dport 4662 --tcp-flags FIN,SYN,RST,ACK SYN -j LOG --log-prefix "SFW2-INext-ACC-TCP " --log-tcp-options --log-ip-options
-A input_ext -p tcp -m tcp --dport 4662 -j ACCEPT
-A input_ext -p udp -m udp --dport 4665 -j ACCEPT
-A input_ext -p udp -m udp --dport 65325 -j ACCEPT
-A input_ext -m pkttype --pkt-type multicast -j DROP
-A input_ext -m pkttype --pkt-type broadcast -j DROP
-A input_ext -p tcp -m limit --limit 3/min -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j LOG --log-prefix "SFW2-INext-DROP-DEFLT " --log-tcp-options --log-ip-options
-A input_ext -p icmp -m limit --limit 3/min -j LOG --log-prefix "SFW2-INext-DROP-DEFLT " --log-tcp-options --log-ip-options
-A input_ext -p udp -m limit --limit 3/min -m state --state NEW -j LOG --log-prefix "SFW2-INext-DROP-DEFLT " --log-tcp-options --log-ip-options
-A input_ext -j DROP
-A reject_func -p tcp -j REJECT --reject-with tcp-reset
-A reject_func -p udp -j REJECT --reject-with icmp-port-unreachable
-A reject_func -j REJECT --reject-with icmp-proto-unreachable
COMMIT
# Completed on Fri Nov 27 16:41:29 2009
In diesem Zusammenhang steht vielleicht, dass ich meine Firewall heute aus irgendwelchen rätselhaften Gründen down vorfand und deshalb neu startete. Hat jemand einen Tipp für mich?