Re: [Shorewall-users] ipv4 spoofing

2020-12-19 Thread Benny Pedersen via Shorewall-users
On 2020-12-20 00:09, bruban...@gmail.com wrote: Perhaps using a VPN? no i only got it private mail here, is sf.net blocking gmail now ? :/ ___ Shorewall-users mailing list Shorewall-users@lists.sourceforge.net https://lists.sourceforge.net/lists/l

Re: [Shorewall-users] ipv4 spoofing

2020-12-19 Thread bruban...@gmail.com
Hi Benny, Perhaps using a VPN? Kind regards, Bruce > On 20 Dec 2020, at 09:18, Benny Pedersen via Shorewall-users > wrote: > > custommers need to use that port, just not from rfc 1918 is my problem to > solve ___ Shorewall-users mailing list Sh

Re: [Shorewall-users] ipv4 spoofing

2020-12-19 Thread Benny Pedersen via Shorewall-users
On 2020-12-10 23:58, Tom Eastep wrote: On 12/10/20 6:02 AM, Benny Pedersen via Shorewall-users wrote: If it is coming from a single address or sub-network, you can simply blacklist the SOURCE. Otherwise, just add a DROP rule that silently drops the traffic from net->fw: DROPnet fw

Re: [Shorewall-users] ipv4 spoofing

2020-12-10 Thread Tom Eastep
On 12/10/20 6:02 AM, Benny Pedersen via Shorewall-users wrote: > > DecĀ  9 18:15:50 localhost kernel: net-fw LOG IN=eth0 OUT= > MAC=f2:3c:92:3b:15:1e:50:87:89:40:a1:c1:08:00 SRC=10.224.98.88 > DST=wan-ip LEN=40 TOS=0x00 PREC=0x00 TTL=54 ID=21571 PROTO=TCP SPT=52652 > DPT=service-port WINDOW=0 RES=0

Re: [Shorewall-users] ipv4 spoofing

2020-12-10 Thread Matt Darfeuille
On 12/10/2020 3:02 PM, Benny Pedersen via Shorewall-users wrote: > > DecĀ  9 18:15:50 localhost kernel: net-fw LOG IN=eth0 OUT= > MAC=f2:3c:92:3b:15:1e:50:87:89:40:a1:c1:08:00 SRC=10.224.98.88 > DST=wan-ip LEN=40 TOS=0x00 PREC=0x00 TTL=54 ID=21571 PROTO=TCP SPT=52652 > DPT=service-port WINDOW=0 RES

[Shorewall-users] ipv4 spoofing

2020-12-10 Thread Benny Pedersen via Shorewall-users
Dec 9 18:15:50 localhost kernel: net-fw LOG IN=eth0 OUT= MAC=f2:3c:92:3b:15:1e:50:87:89:40:a1:c1:08:00 SRC=10.224.98.88 DST=wan-ip LEN=40 TOS=0x00 PREC=0x00 TTL=54 ID=21571 PROTO=TCP SPT=52652 DPT=service-port WINDOW=0 RES=0x00 RST URGP=0 what am i missing in shorewall to stop it ? wan-ip