LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Debian
User Name
Password
Debian This forum is for the discussion of Debian Linux.

Notices


Reply
  Search this Thread
Old 11-01-2004, 03:30 PM   #1
jstreed
LQ Newbie
 
Registered: Aug 2004
Posts: 28

Rep: Reputation: 15
Possible IP tables problem?


When my computer starts, I get the following output in the system log:


I get this message repeadedly when the computer is running. Any ideas as to what is causing this? I thought it was firestarter at first, but removing the program proved me wrong.


Oct 18 13:45:15 localhost kernel: ip_tables: (C) 2000-2002 Netfilter core team
Oct 18 13:45:38 localhost kernel: ip_conntrack version 2.1 (3072 buckets, 24576 max) - 296 bytes per conntrack
Oct 18 13:45:44 localhost kernel: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:0d:56:ca:db:d8:08:00 SRC=170.140.187.141 DST=170.140$Oct 18 13:45:47 localhost kernel: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:03:93:6b:73:10:08:00 SRC=170.140.187.138 DST=170.140$Oct 18 13:45:56 localhost kernel: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:02:b3:48:da:79:08:00 SRC=170.140.186.26 DST=255.255.$Oct 18 13:46:03 localhost kernel: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:03:93:6b:73:10:08:00 SRC=170.140.187.138 DST=170.140$Oct 18 13:46:05 localhost kernel: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:03:93:6b:73:10:08:00 SRC=170.140.187.138 DST=170.140$Oct 18 13:46:10 localhost kernel: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:03:93:6b:73:10:08:00 SRC=170.140.187.138 DST=170.140$Oct 18 13:46:16 localhost kernel: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:0d:56:d6:11:9d:08:00 SRC=170.140.187.136 DST=170.140$Oct 18 13:46:18 localhost kernel: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:03:93:6b:73:10:08:00 SRC=170.140.187.138 DST=170.140$Oct 18 13:46:28 localhost kernel: IN=eth1 OUT= MAC=01:00:5e:00:00:01:00:04:80:58:a2:00:08:00 SRC=170.140.187.254 DST=224.0.0$Oct 18 13:46:29 localhost kernel: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:0b:cd:ad:97:ef:08:00 SRC=170.140.187.94 DST=170.140.$Oct 18 13:46:29 localhost kernel: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:03:ba:5c:c2:20:08:00 SRC=170.140.186.107 DST=170.140$Oct 18 13:46:29 localhost kernel: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:03:ba:5c:c1:e9:08:00 SRC=170.140.186.14 DST=170.140.$Oct 18 13:46:30 localhost kernel: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:0d:56:ca:da:db:08:00 SRC=170.140.187.142 DST=170.140$Oct 18 13:46:30 localhost kernel: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:b0:d0:3d:eb:70:08:00 SRC=170.140.187.80 DST=170.140.$Oct 18 13:46:31 localhost kernel: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:b0:d0:3d:eb:70:08:00 SRC=170.140.187.80 DST=170.140.$Oct 18 13:46:31 localhost kernel: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:03:ba:5c:c2:20:08:00 SRC=170.140.186.107 DST=170.140$Oct 18 13:46:31 localhost kernel: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:03:ba:5c:c2:20:08:00 SRC=170.140.186.107 DST=170.140$Oct 18 13:46:31 localhost kernel: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:03:ba:5c:c1:e9:08:00 SRC=170.140.186.14 DST=170.140.$Oct 18 13:46:31 localhost kernel: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:03:ba:5c:c1:e9:08:00 SRC=170.140.186.14







Thanks



Josh
 
Old 11-01-2004, 05:12 PM   #2
Pcghost
Senior Member
 
Registered: Feb 2003
Location: The Arctic
Distribution: Fedora, Debian, OpenSuSE and Android
Posts: 1,820

Rep: Reputation: 46
Do you have a network card with that mac address? How about those source and destination ip's. I would whois the destination address and see who the machine is talking to.
 
Old 11-02-2004, 10:08 AM   #3
jstreed
LQ Newbie
 
Registered: Aug 2004
Posts: 28

Original Poster
Rep: Reputation: 15
Is there any way I can turn this verbose output off? My network card does have a Mac address, but I don't know what's causing all this crazy output. Similar output it shown on another network, so it isn't related to my network at home.
 
Old 11-02-2004, 11:19 AM   #4
Dead Parrot
Senior Member
 
Registered: Mar 2004
Distribution: Debian GNU/kFreeBSD
Posts: 1,597

Rep: Reputation: 46
You can install ulogd to redirect the firewall log messages into a specific file. In the sticky thread of this forum I have explained how to do this with FireHOL:

http://www.linuxquestions.org/questi...5&pagenumber=1
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
problem concerning Latex-tables Philippe77 Linux - Software 0 11-28-2005 09:12 AM
ip tables problem berrance Linux - Networking 1 03-11-2005 01:56 PM
Newbie IP tables problem benbroad Linux - Security 7 11-29-2004 02:21 PM
ip-tables problem bhagat_panwar Linux - Security 2 08-27-2003 09:29 PM
IP tables problem DonMiner Linux - Networking 7 07-30-2003 09:20 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Debian

All times are GMT -5. The time now is 04:23 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration