All of lore.kernel.org
 help / color / mirror / Atom feed
* pppd Filtering
@ 2004-09-10  9:10 Neil Wilson
  2004-09-10 20:43 ` Clifford Kite
  2004-09-14 21:18 ` Gilles Espinasse
  0 siblings, 2 replies; 3+ messages in thread
From: Neil Wilson @ 2004-09-10  9:10 UTC (permalink / raw)
  To: linux-ppp

Hi Guys,

I have been trying to solve a problem with a server staying online and not
disconnecting, because activity is keeping the link up.

The activity from the /var/log/messages is "IN=ppp0 OUT= MACSRC\x155.239.185.193 DST\x155.239.198.170 LENH TOS=0x00 PREC=0x00 TTL\x123
IDI468 DF PROTO=TCP SPT\x1919 DPTD5 WINDOW‡60 RES=0x00 SYN URGP=0"

As far as I am aware this is activity cause by the Sasser worm trying to get
into my network, and it is getting blocked by the firewall.

I have tried using ppp filtering to stop these,with the line 'active-filter
"not port 445"' in the options.demand file, but this has made no difference.

I have also tried using different syntax's, including adding "inbound" or
"outbound", and I get the following error. "pppd: error in active-filter
expression: inbound/outbound not supported on linktype 0"

Please could someone help me in filtering this activity, so that my server
disconnects when it is supposed to.

I am running slackware 10, with ppp filtering compiled in the kernel by
default, and pppd has the filter option enable also by default.
My idle time is set to 120 in my options.demand file.

Many thanks in advance!

Neil Wilson


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2004-09-14 21:18 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-09-10  9:10 pppd Filtering Neil Wilson
2004-09-10 20:43 ` Clifford Kite
2004-09-14 21:18 ` Gilles Espinasse

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.