Hello!
The kernel and packet logs of my firewall
are filled completly with this messages:
Jul 12 12:07:03 inout kernel: TCP Drop: IN=eth0 OUT=eth1 SRC=192.168.100.11 DST=194.97.51.X LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=2652 DF PROTO=TCP SPT=1105 DPT=80 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 12 12:07:05 inout kernel: UDP Drop: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:01:02:07:e5:74:08:00 SRC=192.168.100.13 DST=192.168.100.255 LEN=229 TOS=0x00 PREC=0x00 TTL=128 ID=33159 PROTO=UDP SPT=138 DPT=138 LEN=209
for my this looks like microsoft-smb packtes (because of the ports 137-139, somethims port 520 (?)).
The problem is that the packets are logt every second,so that the logs are completly full of it.
is this normal???
shell i set a rule to filter them out for dropping without loging?
thanx!
This thread was automatically locked due to age.