I'm seeing the following in my pf logs:
==============================
Sep 15 14:08:49.593449 rule def/(short) pass in on em2:
172.26.20.137.60866 > 172.26.62.1.0: udp 0
Sep 15 14:08:49.809690 rule def/(short) pass in on em2:
172.26.20.137.65148 > 172.26.62.1.0: udp 0
Sep 15 14:09:29.149953 rule def/(short) pass in on em2:
172.26.20.137.49665 > 172.26.62.1.0: udp 0
Sep 15 14:09:29.365757 rule def/(short) pass in on em2:
172.26.20.137.49667 > 172.26.62.1.0: udp 0
Sep 15 14:43:17.717680 rule def/(short) pass in on em2:
172.26.20.137.61884 > 172.26.62.1.0: udp 0
Sep 15 14:43:17.931856 rule def/(short) pass in on em2:
172.26.20.137.61885 > 172.26.62.1.0: udp 0
Sep 15 14:43:47.698013 rule def/(short) pass in on em2:
172.26.20.137.59967 > 172.26.62.1.0: udp 0
Sep 15 14:43:47.911210 rule def/(short) pass in on em2:
172.26.20.137.59968 > 172.26.62.1.0: udp 0
Sep 15 15:09:13.403486 rule def/(short) pass in on em2:
172.26.20.137.49665 > 172.26.62.1.0: udp 0
Sep 15 15:09:13.614937 rule def/(short) pass in on em2:
172.26.20.137.49667 > 172.26.62.1.0: udp 0
Sep 15 15:09:55.807086 rule def/(short) pass in on em2:
172.26.20.137.57674 > 172.26.62.1.0: udp 0
Sep 15 15:09:56.022708 rule def/(short) pass in on em2:
172.26.20.137.57675 > 172.26.62.1.0: udp 0
===============================
The 172.26.20.x subnet is internal and forwarded by a switch to the
default gateway of the OpenBSD router at address 172.26.62.1.
This one system, the only one, regularly attempts these connections to
udp port 0.
Any ideas about why this would occur?

Thank you,
Chris

Reply via email to