besides ASG I'm using Privoxy as a parent proxy (to filter ads).
The Privoxy box (192.168.198.6) is hammering Astaro (192.168.198.1) with some kind of requests:
17:48:25 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38187
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:25 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38187
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:26 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38187
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:27 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38187
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:29 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38187
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:30 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38218
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:30 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38217
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:30 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38215
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:30 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38218
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:30 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38217
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:30 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38215
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:30 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38218
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:30 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38217
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:31 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38215
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:31 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38218
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:31 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38217
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:32 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38215
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:33 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38187
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:33 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38218
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:33 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38217
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:34 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38215
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:37 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38218
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:37 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38217
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:38 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38215
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:39 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38187
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:43 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38218
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
17:48:43 Default DROP TCP 192.168.198.6 : 8118
→ 192.168.198.1 : 38217
[RST] len=40 ttl=64 tos=0x00 srcmac=00:0c:29:5f:75:ff dstmac=00:0c:29:e4:12:5d
Why is Astaro dropping these packets? I have a rule to allow all traffic between internal networks.
And just to be sure I even set up a rule at position 1 to explicitely allow the privoxy box to go anywhere on any port.
Second: Does anyone know of a way how I can find out which application is sending these things? Shutting down the privoxy daemon doesn't help (although it's the process running on port 8118).
This thread was automatically locked due to age.