Web Hosting Talk







View Full Version : logsentry


dutchie
04-22-2002, 03:05 AM
I searched in the archives but could not find anything about it.
What does these lines mean in the logs logsentry sends me every morning ?


(#23) Apr 21 03:53:26 www kernel: Packet log: input DENY eth0 PROTO=17
216.234.186.34:138 216.234.186.255:138 L=232 S=0x00 I=37198 F=0x0000 T=64
(#23) Apr 21 03:53:26 www kernel: Packet log: input DENY eth0 PROTO=17
172.16.70.1:138 172.16.70.255:138 L=239 S=0x00 I=37199 F=0x0000 T=64 (#23)
Apr 21 03:53:26 www kernel: Packet log: input DENY eth0 PROTO=17


There a whole bunch of them, is it anything to worry about ?

rfxn
04-22-2002, 05:30 AM
That seems to be servers sending out Netbios broadcast requests, and as such your firewall (ipchains ?) is configured to drop the packets.

Its nothing to be concerned about however dont start discarding your logs every morning :P

Keep an eye on the firewall logs you get and if you notice a large increase in volume - inspect the situation. Those logs may one day be your best friend in the event of a real attack.