Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 19 Jul 2006 12:07:08 +0300 (EEST)
From:      George Mamalakis <mamalos@lan.gr>
To:        freebsd-security@freebsd.org
Subject:   UDP connection attempts
Message-ID:  <20060719114613.N18979@ns1.lan.gr>

next in thread | raw e-mail | index | archive | help
Hi everyone,
I administer this 5.2.1 Freebsd Box which runs a few services, among of
which are bind and postfix. On the same box I run ipfw as a firewall, and
have a default policy block for all incoming packets, except for those
that are for ports 53 (tcp and udp) and 25 (tcp).
I also have the following sysctl values enabled:
net.inet.tcp.blackhole=2
net.inet.udp.blackhole=1
In my security logs I keep on getting the following messages:
Jul 19 03:04:49 ns1 kernel: Connection attempt to UDP 127.0.0.1:512 from
127.0.0.1:52291
Jul 19 03:25:56 ns1 kernel: Connection attempt to UDP
myexternaladdress:52299 from myexternaladdress:53
Jul 19 09:33:11 ns1 kernel: Connection attempt to UDP
myexternaladdress:52316 from myexternaladdress:53
Jul 19 10:28:32 ns1 kernel: Connection attempt to UDP 127.0.0.1:512 from
127.0.0.1:52328
Jul 19 11:05:49 ns1 kernel: Connection attempt to UDP 127.0.0.1:512 from
127.0.0.1:52354

I have googled these messages many times, but haven't still found a real
explanation of why these messages occur. The way I see it is that there is
no malicious behaviour behind theses messages, most probably there's
something that has to do with my firewall settings, and the keep state
option.
I present the excerpt from my firewall configuration file that relates to
the dns incoming traffic:
add 00389 allow udp from any to myexternaladdress 53 in via fxp0
keep-state

I would be greatful if someone could explain to  me why these messages
keep showing, and if there is a way to prevent them from occuring in the
future.
Thank you all in advance,

mamalos



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20060719114613.N18979>