From: Chris <cpo...@ea...> - 2004-11-09 01:34:13
|
On Monday 08 November 2004 09:36 am, Jan-Peter Koopmann wrote: > On Monday, November 08, 2004 4:07 PM Seanster wrote: > >> pyzor ping > > > > 217.160.253.84:24441 (200, 'OK') > > Ok. I figured it out. I am sending requests to > > 217.160.253.84:24441 but the replys come from > > 82.165.246.93 > > which is why our firewall could not match this to its session table. > > Is this new behaviour? It definately worked without me opening up the > firewall for all inbound traffic to 24441... > Ah, this solves one of the mysteries on my box. My syslog is full of the= se=20 from the past few days: Nov 8 18:06:50 cpollock kernel: IN=3Deth0 OUT=3D=20 MAC=3D00:50:fc:2c:93:ee:00:a0:c5:4a:7b:43:08:00 SRC=3D82.165.246.93=20 DST=3D192.168.1.2 LEN=3D92 TOS=3D0x00 PREC=3D0x00 TTL=3D52 ID=3D0 DF PROT= O=3DUDP=20 SPT=3D24441 DPT=3D47889 LEN=3D72=20 Nov 8 18:15:48 cpollock kernel: IN=3Deth0 OUT=3D=20 MAC=3D00:50:fc:2c:93:ee:00:a0:c5:4a:7b:43:08:00 SRC=3D82.165.246.93=20 DST=3D192.168.1.2 LEN=3D93 TOS=3D0x00 PREC=3D0x00 TTL=3D52 ID=3D0 DF PROT= O=3DUDP=20 SPT=3D24441 DPT=3D47909 LEN=3D73=20 Nov 8 18:19:16 cpollock kernel: IN=3Deth0 OUT=3D=20 MAC=3D00:50:fc:2c:93:ee:00:a0:c5:4a:7b:43:08:00 SRC=3D82.165.246.93=20 DST=3D192.168.1.2 LEN=3D91 TOS=3D0x00 PREC=3D0x00 TTL=3D52 ID=3D0 DF PROT= O=3DUDP=20 SPT=3D24441 DPT=3D47930 LEN=3D71=20 So, which would be the lesser of two evils, opening port 24441 on my=20 firewall or making 82.165.246.93 a trusted host? --=20 Chris Registered Linux User 283774 http://counter.li.org 7:30pm up 4 days, 23:56, 2 users, load average: 1.02, 0.92, 0.73 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Practice yourself what you preach. =09=09-- Titus Maccius Plautus ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Live - From Virgin Radio UK Satus Quo - Whatever you want |