hi again ;-)
i have someone bombing my firewall with:
/date/ kernel: UDP Drop: IN=... OUT=... SRC=/XP-machine/ DST=/ASL-internal/ LEN=160 TOS=0x00 PREC=0x00 TTL=1 ID=24049 PROTO=UDP SPT=39158 DPT=1900 LEN=140
this should be in microsoft-sql-monitor service, so i set a filter for dropping this from any to any...
still got these entries...
and i found something on broadcast adresses like this:
110.255.255.250
???
(together with this winxp-autopnp something...)
how could i set up a broadcast rule to drop these without logging?
i guess i could get that out of memory-error again ....
kind regards,
christian
This thread was automatically locked due to age.