Linux Netfilter discussions
 help / color / mirror / Atom feed
* What does this mean ?
@ 2003-03-19  9:51 Frederic Gobin
  2003-03-19 11:05 ` Raymond Leach
  0 siblings, 1 reply; 6+ messages in thread
From: Frederic Gobin @ 2003-03-19  9:51 UTC (permalink / raw)
  To: netfilter

Hi there everybody,

I have one question :

	Each time I look into my firewall logs, I see many dropped packets 
that match this pattern :

	Protocol 		: TCP
	Source port	: 80
	Dest port		: 1024-65535
	Flags		: ACK FIN

Where are those packets comming from ?

Thanks for reading and Thanks for each answer I get ...

Frederic Gobin



^ permalink raw reply	[flat|nested] 6+ messages in thread
* What does this mean?
@ 2003-02-27 15:06 Raymond Leach
  2003-02-27 15:48 ` Maciej Soltysiak
  0 siblings, 1 reply; 6+ messages in thread
From: Raymond Leach @ 2003-02-27 15:06 UTC (permalink / raw)
  To: Netfilter Mailing List

Hi

I see this in my firewall log:
Feb 27 16:51:19 firefly kernel: DROP FORWARD INTERNAL: IN=eth2 OUT=eth0
SRC=10.0.0.67 DST=68.84.228.144 LEN=60 TOS=0x00 PREC=0x00 TTL=63
ID=64368 DF PROTO=TCP SPT=54767 DPT=0 WINDOW=5840 RES=0x00 CWR ECE SYN
URGP=0

What is DPT=0? I've never heard of using port 0 ...

What is CWR ECE SYN? Are they TCP flags? If so, what is CWR ECE ?

Ray

-- 



^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2003-03-19 11:16 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-03-19  9:51 What does this mean ? Frederic Gobin
2003-03-19 11:05 ` Raymond Leach
2003-03-19 11:16   ` Frederic Gobin
  -- strict thread matches above, loose matches on Subject: below --
2003-02-27 15:06 What does this mean? Raymond Leach
2003-02-27 15:48 ` Maciej Soltysiak
2003-03-05 17:02   ` Alexander W. Janssen

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox