Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Ports 67 & 68 (DHCP)

I have defined a network of 0.0.0.0/255.255.255.255 for local broadcast traffic. I created a rule to allow from the outside these 2 ports, yet continue to get the following drops in my syslog:
kernel: UDP Drop: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00[:D]0:58:7a:7c:54:08:00 SRC=stdhcp01.atl.mediaone.net DST=255.255.255.255 LEN=576 TOS=0x00 PREC=0x00 TTL=250 ID=13950 DF PROTO=UDP SPT=67 DPT=68 LEN=556 

Any ideas?


This thread was automatically locked due to age.
Parents Reply
  • Ok, how about the other direction? I get log entries for src [specific x.x.x.x/32] UDP 67, bcast UDP 68 from a specific source (dchp server). I created a rule to DROP all traffic to all destinations from this source, yet still see the logged packets. The default rule (all, all, all) is also drop. What am I doing wrong?
Children