Hi
I am in desparate need of some help. This is indeed a repost but with a lot more information that might make better sense.
For about a month now I have been getting the following fraffic being dropped and logged on my firewall.
2004:11:16-00:00:09 (none) kernel: DROP: IN=eth0 OUT= MAC=00:06:4f:08:fe:3b:00:c0:02:52:19:46:08:00 SRC=0.0.0.0 DST=0.0.0.0 LEN=40 TOS=0x00 PREC=0x00 TTL=30 ID=28763 PROTO=TCP SPT=0 DPT=0 WINDOW=0 RES=0x00 ACK PSH FIN URGP=0
2004:11:16-00:00:09 (none) kernel: DROP: IN=eth0 OUT= MAC=00:06:4f:08:fe:3b:00:c0:02:52:19:46:08:00 SRC=0.0.0.0 DST=0.0.0.0 LEN=40 TOS=0x00 PREC=0x00 TTL=30 ID=28764 PROTO=TCP SPT=0 DPT=0 WINDOW=0 RES=0x00 ACK PSH FIN URGP=0
2004:11:16-00:00:11 (none) kernel: DROP: IN=eth0 OUT= MAC=00:06:4f:08:fe:3b:00:c0:02:52:19:46:08:00 SRC=0.0.0.0 DST=0.0.0.0 LEN=40 TOS=0x00 PREC=0x00 TTL=30 ID=28765 PROTO=TCP SPT=0 DPT=0 WINDOW=0 RES=0x00 ACK PSH FIN URGP=0
2004:11:16-00:00:12 (none) kernel: DROP: IN=eth0 OUT= MAC=00:06:4f:08:fe:3b:00:c0:02:52:19:46:08:00 SRC=0.0.0.0 DST=0.0.0.0 LEN=40 TOS=0x00 PREC=0x00 TTL=30 ID=28766 PROTO=TCP SPT=0 DPT=0 WINDOW=0 RES=0x00 ACK PSH FIN URGP=0
2004:11:16-00:00:12 (none) kernel: DROP: IN=eth0 OUT= MAC=00:06:4f:08:fe:3b:00:c0:02:52:19:46:08:00 SRC=0.0.0.0 DST=0.0.0.0 LEN=40 TOS=0x00 PREC=0x00 TTL=30 ID=28767 PROTO=TCP SPT=0 DPT=0 WINDOW=0 RES=0x00 ACK PSH FIN URGP=0
2004:11:16-00:00:14 (none) kernel: DROP: IN=eth0 OUT= MAC=00:06:4f:08:fe:3b:00:c0:02:52:19:46:08:00 SRC=0.0.0.0 DST=0.0.0.0 LEN=40 TOS=0x00 PREC=0x00 TTL=30 ID=28768 PROTO=TCP SPT=0 DPT=0 WINDOW=0 RES=0x00 ACK PSH FIN URGP=0
2004:11:16-00:00:15 (none) kernel: DROP: IN=eth0 OUT= MAC=00:06:4f:08:fe:3b:00:c0:02:52:19:46:08:00 SRC=0.0.0.0 DST=0.0.0.0 LEN=40 TOS=0x00 PREC=0x00 TTL=30 ID=28769 PROTO=TCP SPT=0 DPT=0 WINDOW=0 RES=0x00 ACK PSH FIN URGP=0
2004:11:16-00:00:15 (none) kernel: DROP: IN=eth0 OUT= MAC=00:06:4f:08:fe:3b:00:c0:02:52:19:46:08:00 SRC=0.0.0.0 DST=0.0.0.0 LEN=40 TOS=0x00 PREC=0x00 TTL=30 ID=28770 PROTO=TCP SPT=0 DPT=0 WINDOW=0 RES=0x00 ACK PSH FIN URGP=0
2004:11:16-00:00:17 (none) kernel: DROP: IN=eth0 OUT= MAC=00:06:4f:08:fe:3b:00:c0:02:52:19:46:08:00 SRC=0.0.0.0 DST=0.0.0.0 LEN=40 TOS=0x00 PREC=0x00 TTL=30 ID=28772 PROTO=TCP SPT=0 DPT=0 WINDOW=0 RES=0x00 ACK PSH FIN URGP=0
2004:11:16-00:00:18 (none) kernel: DROP: IN=eth0 OUT= MAC=00:06:4f:08:fe:3b:00:c0:02:52:19:46:08:00 SRC=0.0.0.0 DST=0.0.0.0 LEN=40 TOS=0x00 PREC=0x00 TTL=30 ID=28773 PROTO=TCP SPT=0 DPT=0 WINDOW=0 RES=0x00 ACK PSH FIN URGP=0
2004:11:16-00:00:18 (none) kernel: DROP: IN=eth0 OUT= MAC=00:06:4f:08:fe:3b:00:c0:02:52:19:46:08:00 SRC=0.0.0.0 DST=0.0.0.0 LEN=40 TOS=0x00 PREC=0x00 TTL=30 ID=28774 PROTO=TCP SPT=0 DPT=0 WINDOW=0 RES=0x00 ACK PSH FIN URGP=0
2004:11:16-00:00:20 (none) kernel: DROP: IN=eth0 OUT= MAC=00:06:4f:08:fe:3b:00:c0:02:52:19:46:08:00 SRC=0.0.0.0 DST=0.0.0.0 LEN=40 TOS=0x00 PREC=0x00 TTL=30 ID=28775 PROTO=TCP SPT=0 DPT=0 WINDOW=0 RES=0x00 ACK PSH FIN URGP=0
2004:11:16-00:00:21 (none) kernel: DROP: IN=eth0 OUT= MAC=00:06:4f:08:fe:3b:00:c0:02:52:19:46:08:00 SRC=0.0.0.0 DST=0.0.0.0 LEN=40 TOS=0x00 PREC=0x00 TTL=30 ID=28776 PROTO=TCP SPT=0 DPT=0 WINDOW=0 RES=0x00 ACK PSH FIN URGP=0
2004:11:16-00:00:21 (none) kernel: DROP: IN=eth0 OUT= MAC=00:06:4f:08:fe:3b:00:c0:02:52:19:46:08:00 SRC=0.0.0.0 DST=0.0.0.0 LEN=40 TOS=0x00 PREC=0x00 TTL=30 ID=28777 PROTO=TCP SPT=0 DPT=0 WINDOW=0 RES=0x00 ACK PSH FIN URGP=0
I have no idea where this traffic is coming from.
I am getting the above constantly and can not find a way of stopping it or at least stopping the logging of the drop.
Can anyone help. I apologise for the repost but I am desparate to nip this in the bud
Cheers
Mike
This thread was automatically locked due to age.