Hi all,
I'm quiet new with Astaro product so ... I have some question for you guys...
I've installed ASL 4.0 (applied all the patches) ... and when I check the filtering log I got thhis information which seems to be a puzzle for me ... :
2004-Apr 9 00:02:19 (none) kernel: UDP Drop: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:09:12:82:6c:54:08:00 SRC=10.67.64.1 DST=255.255.255.255 LEN=358 TOS=0x00 PREC=0x00 TTL=255 ID=27106 PROTO=UDP SPT=67 DPT=68 LEN=338
2004-Apr 9 00:02:22 (none) kernel: UDP Drop: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:09:12:82:6c:54:08:00 SRC=10.67.64.1 DST=255.255.255.255 LEN=358 TOS=0x00 PREC=0x00 TTL=255 ID=27112 PROTO=UDP SPT=67 DPT=68 LEN=338
2004-Apr 9 00:06:48 (none) kernel: UDP Drop: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:09:12:82:6c:54:08:00 SRC=10.67.64.1 DST=255.255.255.255 LEN=382 TOS=0x00 PREC=0x00 TTL=255 ID=28101 PROTO=UDP SPT=67 DPT=68 LEN=362
2004-Apr 9 00:06:48 (none) kernel: UDP Drop: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:09:12:82:6c:54:08:00 SRC=10.67.64.1 DST=255.255.255.255 LEN=382 TOS=0x00 PREC=0x00 TTL=255 ID=28105 PROTO=UDP SPT=67 DPT=68 LEN=362
2004-Apr 9 00:07:34 (none) kernel: UDP Drop: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:09:12:82:6c:54:08:00 SRC=10.67.64.1 DST=255.255.255.255 LEN=382 TOS=0x00 PREC=0x00 TTL=255 ID=28275 PROTO=UDP SPT=67 DPT=68 LEN=362
2004-Apr 9 00:08:01 (none) kernel: UDP Drop: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:09:12:82:6c:54:08:00 SRC=10.67.64.1 DST=255.255.255.255 LEN=382 TOS=0x00 PREC=0x00 TTL=255 ID=28378 PROTO=UDP SPT=67 DPT=68 LEN=362
2004-Apr 9 00:08:01 (none) kernel: UDP Drop: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:09:12:82:6c:54:08:00 SRC=10.67.64.1 DST=255.255.255.255 LEN=382 TOS=0x00 PREC=0x00 TTL=255 ID=28382 PROTO=UDP SPT=67 DPT=68 LEN=362
2004-Apr 9 00:08:58 (none) kernel: UDP Drop: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:09:12:82:6c:54:08:00 SRC=10.67.64.1 DST=255.255.255.255 LEN=400 TOS=0x00 PREC=0x00 TTL=255 ID=28652 PROTO=UDP SPT=67 DPT=68 LEN=380
2004-Apr 9 00:08:59 (none) kernel: UDP Drop: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:09:12:82:6c:54:08:00 SRC=10.67.64.1 DST=255.255.255.255 LEN=399 TOS=0x00 PREC=0x00 TTL=255 ID=28688 PROTO=UDP SPT=67 DPT=68 LEN=379
2004-Apr 9 00:09:00 (none) kernel: UDP Drop: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:09:12:82:6c:54:08:00 SRC=10.67.64.1 DST=255.255.255.255 LEN=400 TOS=0x00 PREC=0x00 TTL=255 ID=28708 PROTO=UDP SPT=67 DPT=68 LEN=380
2004-Apr 9 00:09:00 (none) kernel: UDP Drop: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:09:12:82:6c:54:08:00 SRC=10.67.64.1 DST=255.255.255.255 LEN=400 TOS=0x00 PREC=0x00 TTL=255 ID=28712 PROTO=UDP SPT=67 DPT=68 LEN=380
2004-Apr 9 00:09:01 (none) kernel: UDP Drop: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:09:12:82:6c:54:08:00 SRC=10.67.64.1 DST=255.255.255.255 LEN=400 TOS=0x00 PREC=0x00 TTL=255 ID=28736 PROTO=UDP SPT=67 DPT=68 LEN=380
2004-Apr 9 00:09:01 (none) kernel: UDP Drop: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:09:12:82:6c:54:08:00 SRC=10.67.64.1 DST=255.255.255.255 LEN=399 TOS=0x00 PREC=0x00 TTL=255 ID=28752 PROTO=UDP SPT=67 DPT=68 LEN=379
2004-Apr 9 00:09:01 (none) kernel: UDP Drop: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:09:12:82:6c:54:08:00 SRC=10.67.64.1 DST=255.255.255.255 LEN=399 TOS=0x00 PREC=0x00 TTL=255 ID=28756 PROTO=UDP SPT=67 DPT=68 LEN=379
2004-Apr 9 00:09:01 (none) kernel: UDP Drop: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:09:12:82:6c:54:08:00 SRC=10.67.64.1 DST=255.255.255.255 LEN=400 TOS=0x00 PREC=0x00 TTL=255 ID=28760 PROTO=UDP SPT=67 DPT=68 LEN=380
Seems to me like a port scanning ... but ... I don't have anything in my internal network having an IP : 10.67.64.1 ...
Could somebody tell me what's all this about ... [:$] ...
Best regards to all and a Happy Easter
This thread was automatically locked due to age.