![](https://seccdn.libravatar.org/avatar/abdee805d4df05af9a496107100c582c.jpg?s=120&d=mm&r=g)
for the last several days, my firewall logs have exploded with entries about 224.0.0.1 (about multi-cast ??) access from my router: Apr 5 00:57:48 wahoo kernel: [4531053.824463] SFW2-INext-ACC-TRUST IN=eth0 OUT= MAC=01:00:5e:00:00:01:c0:c1:c0:b4:ea:1e:08:00 SRC=192.168.1.1 DST=224.0.0.1 LEN=28 TOS=0x00 PREC=0x00 TTL=1 ID=0 DF PROTO=2 Apr 5 00:59:54 wahoo kernel: [4531179.825578] SFW2-INext-ACC-TRUST IN=eth0 OUT= MAC=01:00:5e:00:00:01:c0:c1:c0:b4:ea:1e:08:00 SRC=192.168.1.1 DST=224.0.0.1 LEN=28 TOS=0x00 PREC=0x00 TTL=1 ID=0 DF PROTO=2 Apr 5 01:02:00 wahoo kernel: [4531305.826723] SFW2-INext-ACC-TRUST IN=eth0 OUT= MAC=01:00:5e:00:00:01:c0:c1:c0:b4:ea:1e:08:00 SRC=192.168.1.1 DST=224.0.0.1 LEN=28 TOS=0x00 PREC=0x00 TTL=1 ID=0 DF PROTO=2 Apr 5 01:04:06 wahoo kernel: [4531431.827802] SFW2-INext-ACC-TRUST IN=eth0 OUT= MAC=01:00:5e:00:00:01:c0:c1:c0:b4:ea:1e:08:00 SRC=192.168.1.1 DST=224.0.0.1 LEN=28 TOS=0x00 PREC=0x00 TTL=1 ID=0 DF PROTO=2 I have not made any changes to this server recently. Why am I suddenly seeing these entries, and what do to about it? What I have tried from googling has not worked... iptables -A INPUT -s 224.0.0.1 -p tcp --dport 2 -j REJECT But on the surface this makes no sense as the origin/input is the router, 192.168.1.1, and the destination is 224.0.0.1 But what do I know ??? :^) *very* little tks, -- (paka)Patrick Shanahan Plainfield, Indiana, USA HOG # US1244711 http://wahoo.no-ip.org Photo Album: http://wahoo.no-ip.org/gallery2 http://en.opensuse.org openSUSE Community Member Registered Linux User #207535 @ http://linuxcounter.net -- To unsubscribe, e-mail: opensuse+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse+owner@opensuse.org