Hi,
Using 4.4.23.2 on a single host. A host x.x.x.x is sending traffic
although it blacklisted and blocked rules
rules:
DROP net:x.x.x.x/21 $FW - - -
DROP net:x.x.x.x/22 $FW - - -
DROP $FW net:x.x.x.x/21 - - -
DROP $FW net:x.x.x.x/22 - - -
blackist
#ADDRESS/SUBNET PROTOCOL PORT OPTIONS
x.x.x.x/21 - - src,dst
x.x.x.x/22 - - src,dst
I see no record of the host in the logs. App darkstat indicates that
host is sending traffic on random udp ports and it shows when last the
host connected and the amount of traffic. This is a little puzzling. Is
the something I am overlooking.
Regards
/K
------------------------------------------------------------------------------
All the data continuously generated in your IT infrastructure
contains a definitive record of customers, application performance,
security threats, fraudulent activity, and more. Splunk takes this
data and makes sense of it. IT sense. And common sense.
http://p.sf.net/sfu/splunk-novd2d
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users