SuSEfirewall2 logs
Hello! I have tons of these logs lines in my messages file: Aug 28 23:00:09 linux kernel: SuSE-FW-UNALLOWED-ROUTINGIN=ppp0 OUT=eth1 SRC=80.11.184.192 DST=192.168.1.40 LEN=46 TOS=0x00 PREC=0x00 TTL=116 ID=65170 DF PROTO=TCP SPT=16392 DPT=4Aug 28 23:00:09 linux kernel: SuSE-FW-UNALLOWED-ROUTINGIN=eth1 OUT=ppp0 SRC=192.168.1.40 DST=172.179.119.14 LEN=45 TOS=0x00 PREC=0x00 TTL=63 ID=21103 DF PROTO=TCP SPT=4662 DPT=10Aug 28 23:00:09 linux kernel: SuSE-FW-UNALLOWED-ROUTINGIN=eth1 OUT=ppp0 SRC=192.168.1.40 DST=217.225.201.254 LEN=57 TOS=0x00 PREC=0x00 TTL=63 ID=60841 DF PROTO=TCP SPT=4662 DPT=1Aug 28 23:00:09 linux kernel: SuSE-FW-UNALLOWED-ROUTINGIN=ppp0 OUT=eth1 SRC=217.81.190.199 DST=192.168.1.40 LEN=63 TOS=0x00 PREC=0x00 TTL=123 ID=31363 DF PROTO=TCP SPT=3300 DPT=4Aug 28 23:00:10 linux kernel: SuSE-FW-UNALLOWED-ROUTINGIN=eth1 OUT=ppp0 SRC=192.168.1.40 DST=217.235.27.95 LEN=196 TOS=0x00 PREC=0x00 TTL=63 ID=46387 DF PROTO=TCP SPT=4662 DPT=20Aug 28 23:00:10 linux kernel: SuSE-FW-UNALLOWED-TARGETIN=ppp0 OUT= MAC= SRC=213.41.190.50 DST=80.145.118.9 LEN=52 TOS=0x00 PREC=0x00 TTL=119 ID=52022 DF PROTO=TCP SPT=4627 DPT=46Aug 28 23:00:11 linux kernel: SuSE-FW-UNALLOWED-ROUTINGIN=ppp0 OUT=eth1 SRC=62.225.224.78 DST=192.168.1.40 LEN=132 TOS=0x00 PREC=0x00 TTL=123 ID=46413 DF PROTO=TCP SPT=3260 DPT=4Aug 28 23:00:11 linux kernel: SuSE-FW-UNALLOWED-ROUTINGIN=ppp0 OUT=eth1 SRC=80.11.184.192 DST=192.168.1.40 LEN=46 TOS=0x00 PREC=0x00 TTL=116 ID=65300 DF PROTO=TCP SPT=16392 DPT=4Aug 28 23:00:11 linux kernel: SuSE-FW-UNALLOWED-ROUTINGIN=eth1 OUT=ppp0 SRC=192.168.1.40 DST=80.14.103.72 LEN=45 TOS=0x00 PREC=0x00 TTL=63 ID=27602 DF PROTO=TCP SPT=4662 DPT=6506 My Firewall nics: ------------------------ eth0 Link encap:Ethernet HWaddr 00:80:48:C5:C9:11 inet addr:192.168.2.254 Bcast:192.168.2.255 Mask:255.255.255.0 eth1 Link encap:Ethernet HWaddr 00:00:21:FE:4C:14 inet addr:192.168.1.254 Bcast:192.168.1.255 Mask:255.255.255.0 eth2 Link encap:Ethernet HWaddr 00:30:84:74:AE:52 inet addr:192.168.0.99 Bcast:192.168.0.255 Mask:255.255.255.0 ppp0 Link encap:Point-to-Point Protocol inet addr:80.145.118.9 P-t-P:217.5.98.130 Mask:255.255.255.255 I am not sure if i should disable these entrys (well, i dont know how to do that anyway), but in the other case they might be important. Or is this a kind of misconfigures network. Thanks! Mario
participants (1)
-
Mario Ohnewald