/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


I had a similar problem and cued it by blocking ports 138 and 139 as well 
as 137 but if blocking ports 137 and 138 stops the unwanted dialing, do not 
bother with 139. I only block port 139 for completeness but use whatever 
works for you.

Here is what I think is happening.

Log line 1.
192.168.10.1 is broadcasting a request on port 138 (nbdatagram).

Log line 2.
192.168.10.20 (DNS server????) is requesting a lookup from 195.243.188.5 
Check the logs on your DNS server, you may find that 1135 is the port it is 
using to send out requests on.

Log line 3.
Not sure what is going on here but another request to the remote DNS 
server, may be opening a socket or port on the gateway machine (this computer?)

log line 4.
PPP connection opening.

At 10:16 29/04/00 , Thomas Papenkort wrote:
>Here is a part of my logfile:
> > Apr 18 20:07:21 server kernel: Packet log: input - eth0 PROTO=17 
> 192.168.10.1:138 192.168.10.255:138 L=217 S=0x00 I=482 F=0x0000 T=64 (#1)
> > Apr 18 20:07:23 server kernel: Packet log: input - eth0 PROTO=17 
> 192.168.10.20:1135 195.243.188.5:53 L=59 S=0x00 I=23309 F=0x0000 T=32 (#1)
> > Apr 18 20:07:23 server kernel: OPEN: 192.168.10.99 -> 195.243.188.5 
> UDP, port: 61097 -> 53
> > Apr 18 20:07:23 server kernel: ippp0: dialing 1 0215255...

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to