Hi,

Using 4.4.23.2 on a single host. A host x.x.x.x is sending traffic although it blacklisted and blocked rules

rules:

DROP                net:x.x.x.x/21     $FW         -       -       -
DROP                net:x.x.x.x/22     $FW         -       -       -
DROP                $FW         net:x.x.x.x/21     -       -       -
DROP                $FW         net:x.x.x.x/22     -       -       -

blackist

#ADDRESS/SUBNET     PROTOCOL    PORT    OPTIONS
x.x.x.x/21     -           -       src,dst
x.x.x.x/22     -           -       src,dst

I see no record of the host in the logs. App darkstat indicates that host is sending traffic on random udp ports and it shows when last the host connected and the amount of traffic. This is a little puzzling. Is the something I am overlooking.

Regards

/K










------------------------------------------------------------------------------
All the data continuously generated in your IT infrastructure 
contains a definitive record of customers, application performance, 
security threats, fraudulent activity, and more. Splunk takes this 
data and makes sense of it. IT sense. And common sense.
http://p.sf.net/sfu/splunk-novd2d
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to