LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 10-10-2006, 12:58 PM   #1
taddytak
LQ Newbie
 
Registered: Oct 2006
Posts: 1

Rep: Reputation: 0
meaning of logs


hi guys,

I have just configured an arno's iptables firewall on redhat9 and these are logs am getting from my /var/log/messages.

Connection attempt (PRIV): IN=ppp0 OUT= MAC= SRC=x.x.x.x DST=x.x.x.x LEN=458 TOS=0x00 PREC=0x00 TTL=48 ID=0 DF PROTO=UDP SPT=56228 DPT=1027 LEN=438
Connection attempt (PRIV): IN=ppp0 OUT= MAC= SRC=x.x.x.x DST=x.x.x.x LEN=458 TOS=0x00 PREC=0x00 TTL=48 ID=0 DF PROTO=UDP SPT=56229 DPT=1026 LEN=438
Connection attempt (UNPRIV): IN=ppp0 OUT= MAC= SRC=x.x.x.x DST=x.x.x.x LEN=48 TOS=0x00 PREC=0x00 TTL=108 ID=23827 DF PROTO=TCP SPT=3292 DPT=1608 WINDOW=32000 RES=0x00 SYN URGP=0

What does this mean? Is there any difference betwwen PRIV and UNPRIV? what happening here?
 
Old 10-10-2006, 04:09 PM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
they are attempts from a source to conenct to a destination which is matching a rule on your iptables setup. now i'd have to assume that you have a 56k modem and a connection to your isp and you're being port scanned... PRIV means a port under 1024, UNPRIV means a port over it. the first 1024 ports are theoretically reserved for priveleged services, not services that a normal user may be able to start.

if you wish to stop these messages, i think it's a case of running "dmesg -n1" to change the sensitivity of the kernel log ring buffer
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Ubuntu logs on, then logs back off generallee5686 Ubuntu 0 10-20-2005 01:11 PM
Firewall logs in logs and terminal... robbow52 Debian 7 11-20-2004 07:13 PM
Firefox logs user out? Where are error logs? case1984 Linux - General 0 10-09-2004 02:22 PM
Separate firewall logs and general logs dominant Linux - General 3 04-20-2004 01:26 AM
Apache logs - ???Linux logs??? mylo2003 Linux - General 3 08-07-2003 04:49 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 04:51 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration