From owner-freebsd-questions@FreeBSD.ORG Thu Apr 10 18:55:18 2008 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id B7792106564A for ; Thu, 10 Apr 2008 18:55:18 +0000 (UTC) (envelope-from bitabyss@gmail.com) Received: from cartman.xxiii.com (cartman.xxiii.com [208.62.177.45]) by mx1.freebsd.org (Postfix) with ESMTP id 761D98FC16 for ; Thu, 10 Apr 2008 18:55:18 +0000 (UTC) (envelope-from bitabyss@gmail.com) Received: from [172.23.23.190] (lan23.xxiii.com [208.62.177.50]) by cartman.xxiii.com (8.13.8/8.13.8) with ESMTP id m3AIcrkL005775 for ; Thu, 10 Apr 2008 14:38:53 -0400 (EDT) (envelope-from bitabyss@gmail.com) Message-ID: <47FE5EC1.7000809@gmail.com> Date: Thu, 10 Apr 2008 14:38:57 -0400 From: Rob User-Agent: Thunderbird 1.5.0.14 (Windows/20071210) MIME-Version: 1.0 To: FreeBSD Questions Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Subject: ipfw denial log - what's this mean? X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 10 Apr 2008 18:55:18 -0000 Hi Everyone, My 6.2-Release system coughed up a report of denied packets from ipfw in its daily security run: ipfw denied packets: +++ /tmp/security.gnkQg5CA Thu Apr 10 03:04:15 2008 +00200 12 795 deny ip from any to 127.0.0.0/8 What does this mean? I understand that's the loopback interface, but I'm not terribly knowledgeable on ipfw. Is this some crack attempt, or normal background noise? I don't understand how lo0 would ever see any IP addresses other than its own?! The whole rule set looks like this: # ipfw show 00100 4749394 1011660210 allow ip from any to any via lo0 00200 12 795 deny ip from any to 127.0.0.0/8 00300 0 0 deny ip from 127.0.0.0/8 to any 01005 17272713 2535346056 fwd 12.219.128.1 tcp from 12.219.128.39 to any out 65000 174044808 81045388703 allow ip from any to any 65535 1 328 deny ip from any to any -Thanks, Rob