LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-18-2010, 08:15 AM   #1
spandey
LQ Newbie
 
Registered: Sep 2010
Posts: 28

Rep: Reputation: 0
UFW messages in 100s of Thousands in an hour


I am newbie in Linux using Mint 9 Isadora. I am flooded with UFW messages. I would like to how to interpret these messages. I am a bit scared..
 
Old 09-18-2010, 11:16 AM   #2
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,666

Rep: Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970
Quote:
Originally Posted by spandey View Post
I am newbie in Linux using Mint 9 Isadora. I am flooded with UFW messages. I would like to how to interpret these messages. I am a bit scared..
Not much anyone can do for you, based on your question. You don't tell us about your environment, where this machine is, how long it's been going on, or even provide a sample of these messages. We don't know what services are running on that box, or what you've looked at so far.

Provide details, and perhaps we can help.
 
Old 09-18-2010, 07:28 PM   #3
spandey
LQ Newbie
 
Registered: Sep 2010
Posts: 28

Original Poster
Rep: Reputation: 0
Sorry I was in panic mode..Here are some info..

I am using this dekstop for personal use. My PC is connected to DSL modem via ethernet. The modem is in Bridge mode and I need to connect using Network Manager. There are no routers involved.

Linux Mint Isadora is installed. Default UFW is on. I am trying to find out manual for output SYNTAX of UFW so that I can interpret each one and try to findout what it is rather than asking questions again and again.

some samples...
Sep 18 18:11:17 spandey-desktop kernel: [ 108.412242] [UFW BLOCK] IN=ppp0 OUT= MAC= SRC=203.77.189.88 DST=117.197.238.169 LEN=1460 TOS=0x00 PREC=0x20 TTL=55 ID=13459 DF PROTO=TCP SPT=80 DPT=3859 WINDOW=12513 RES=0x00 ACK URGP=0
Sep 18 18:11:17 spandey-desktop kernel: [ 108.419297] [UFW AUDIT] IN=ppp0 OUT= MAC= SRC=203.77.189.88 DST=117.197.238.169 LEN=1460 TOS=0x00 PREC=0x20 TTL=55 ID=13460 DF PROTO=TCP SPT=80 DPT=3859 WINDOW=12513 RES=0x00 ACK URGP=0
Sep 18 18:11:17 spandey-desktop kernel: [ 108.419315] [UFW BLOCK] IN=ppp0 OUT= MAC= SRC=203.77.189.88 DST=117.197.238.169 LEN=1460 TOS=0x00 PREC=0x20 TTL=55 ID=13460 DF PROTO=TCP SPT=80 DPT=3859 WINDOW=12513 RES=0x00 ACK URGP=0
---------------------------------------------------------------
 
Old 09-19-2010, 10:12 AM   #4
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,666

Rep: Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970
Quote:
Originally Posted by spandey View Post
Sorry I was in panic mode..Here are some info..

I am using this dekstop for personal use. My PC is connected to DSL modem via ethernet. The modem is in Bridge mode and I need to connect using Network Manager. There are no routers involved.

Linux Mint Isadora is installed. Default UFW is on. I am trying to find out manual for output SYNTAX of UFW so that I can interpret each one and try to findout what it is rather than asking questions again and again.
Panic mode is never helpful, espeically when you don't know if you NEED to panic.

Some things that will help you:
https://help.ubuntu.com/10.04/server.../firewall.html
http://manpages.ubuntu.com/manpages/...an8/ufw.8.html

Explains operation of the firewall, and how to set/check logs. If you've enabled logging of anything over MEDIUM, you'll get lots of messages. Setting to LOW is usually recommended.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Cron job issue - every hour works, but specific hour fails lunarleviathan Linux - Newbie 6 11-20-2009 12:19 AM
Cant get networkcard to work (intell pro 100s) BladeFireLight Linux - Networking 8 01-11-2006 02:13 PM
Aergh. X dies on the hour, every hour l00zer Linux - Software 4 06-07-2005 10:02 PM
Compaq Armada 100s jsien Linux - Newbie 1 03-19-2005 05:49 AM
change clock from 24 hour to 12 hour in suse 9.2/KDE 3.3 jmlumpkin Linux - Newbie 1 01-22-2005 11:45 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:16 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration