- 论坛徽章:
- 0
|
Hi everyone
my firewall have some problem, did anyone help me ?
i accept squid read 80 port from internet.
but in my log file, i found some (not all) packet from Source port 80 and iptables reject them? '
why
---------------------
Rhel3
[root@mail root]# rpm -q iptables
iptables-1.2.8-12
-----------------------
-------------------------------------
My iptables setting
---------------------------------------
'Chain RH-Firewall-1-INPUT (2 references)
pkts bytes target prot opt in out source destination
1807K 150M ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
40M 6735M ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
839 278K ACCEPT udp -- eth1 * 0.0.0.0/0 0.0.0.0/0 state NEW udp spt:53
6 240 ACCEPT tcp -- eth1 * 0.0.0.0/0 0.0.0.0/0 state NEW tcp spt:1521
929 40074 ACCEPT tcp -- eth1 * 0.0.0.0/0 0.0.0.0/0 state NEW tcp spt:80
32 1280 ACCEPT tcp -- eth1 * 0.0.0.0/0 0.0.0.0/0 state NEW tcp spt:443
0 0 REJECT udp -- eth1 * 0.0.0.0/0 0.0.0.0/0 state NEW udp spt:67 reject-with icmp-port-unreachable
0 0 REJECT udp -- eth1 * 0.0.0.0/0 0.0.0.0/0 state NEW udp spt:68 reject-with icmp-port-unreachable
1680 67200 LOG all -- eth1 * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 0 prefix `'FW-eth1''
1680 67200 REJECT all -- eth1 * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-prohibited
-------------------------
----------------------------
[root@mail root]# dmesg
5 LEN=40 TOS=0x00 PREC=0x00 TTL=254 ID=0 DF PROTO=TCP SPT=80 DPT=42195 WINDOW=0 RES=0x00 RST URGP=0
'FW-eth1'IN=eth1 OUT= MAC=00:0d:60:1a:1f:2b:00:50:7f:06:d6:1a:08:00 SRC=61.172.201.224 DST=192.168.1.5 LEN=40 TOS=0x00 PREC=0x00 TTL=254 ID=0 DF PROTO=TCP SPT=80 DPT=42183 WINDOW=0 RES=0x00 RST URGP=0
'FW-eth1'IN=eth1 OUT= MAC=00:0d:60:1a:1f:2b:00:50:7f:06:d6:1a:08:00 SRC=216.239.63.91 DST=192.168.1.5 LEN=40 TOS=0x00 PREC=0x00 TTL=254 ID=0 DF PROTO=TCP SPT=80 DPT=42194 WINDOW=0 RES=0x00 RST URGP=0
'FW-eth1'IN=eth1 OUT= MAC=00:0d:60:1a:1f:2b:00:50:7f:06:d6:1a:08:00 SRC=216.239.63.93 DST=192.168.1.5 LEN=40 TOS=0x00 PREC=0x00 TTL=254 ID=0 DF PROTO=TCP SPT=80 DPT=42193 WINDOW=0 RES=0x00 RST URGP=0
'FW-eth1'IN=eth1 OUT= MAC=00:0d:60:1a:1f:2b:00:50:7f:06:d6:1a:08:00 SRC=216.239.63.91 DST=192.168.1.5 LEN=40 TOS=0x00 PREC=0x00 TTL=254 ID=0 DF PROTO=TCP SPT=80 DPT=42192 WINDOW=0 RES=0x00 RST URGP=0
'FW-eth1'IN=eth1 OUT= MAC=00:0d:60:1a:1f:2b:00:50:7f:06:d6:1a:08:00 SRC=216.239.63.93 DST=192.168.1.5 LEN=40 TOS=0x00 PREC=0x00 TTL=254 ID=0 DF PROTO=TCP SPT=80 DPT=42191 WINDOW=0 RES=0x00 RST URGP=0
'FW-eth1'IN=eth1 OUT= MAC=00:0d:60:1a:1f:2b:00:50:7f:06:d6:1a:08:00 SRC=216.239.63.93 DST=192.168.1.5 LEN=40 TOS=0x00 PREC=0x00 TTL=254 ID=0 DF PROTO=TCP SPT=80 DPT=42125 WINDOW=0 RES=0x00 RST URGP=0
'FW-eth1'IN=eth1 OUT= MAC=00:0d:60:1a:1f:2b:00:50:7f:06:d6:1a:08:00 SRC=216.239.63.91 DST=192.168.1.5 LEN=40 TOS=0x00 PREC=0x00 TTL=254 ID=0 PROTO=TCP SPT=80 DPT=42017 WINDOW=0 RES=0x00 RST URGP=0
'------------------ |
|