First – hello all of you!
Next - my problem. I googled a bit but I could not get very clear ideas and that’s why I decided to post a question. We’re running a small Windows network NAT-ed by an openSUSE gateway. eth0 is the external interface, eht1 – the internal. There are a lot of logged “martians” in /var/log/messages. Actually 10 martians arrive each 15 seconds or so and pollute our precious log. Here is part of it:
Apr 1 08:56:52 gateway kernel: martian source 77.61.167.146 from 0.0.0.0, on dev eth0
Apr 1 08:56:52 gateway kernel: ll header: ff:ff:ff:ff:ff:ff:00:30:48:85:17:b9:08:00
Apr 1 08:57:09 gateway kernel: martian destination 0.0.0.0 from 75.193.144.186, dev eth0
Apr 1 08:57:09 gateway kernel: martian source 75.193.144.186 from 0.0.0.0, on dev eth0
Apr 1 08:57:09 gateway kernel: ll header: ff:ff:ff:ff:ff:ff:00:30:48:85:17:b9:08:00
Apr 1 08:57:26 gateway kernel: martian destination 0.0.0.0 from 81.36.130.25, dev eth0
Apr 1 08:57:26 gateway kernel: martian source 81.36.130.25 from 0.0.0.0, on dev eth0
Apr 1 08:57:26 gateway kernel: ll header: ff:ff:ff:ff:ff:ff:00:30:48:85:17:b9:08:00
Apr 1 08:57:45 gateway kernel: martian destination 0.0.0.0 from 92.126.165.236, dev eth0
Apr 1 08:57:45 gateway kernel: martian source 92.126.165.236 from 0.0.0.0, on dev eth0
Apr 1 08:57:45 gateway kernel: ll header: ff:ff:ff:ff:ff:ff:00:30:48:85:17:b9:08:00
I wrote a letter to my ISP and they admitted that 00:30:48:85:17:b9 was the MAC of their gateway (our default route – a single entry in the /etc/sysconfig/network/routes). The rest of their reaction was quite unprofessional “why don’t you just switch the logging of martians off?”. No log – no problem. And I temporary did it
The EtherType 08:00 marks an IP packet.
Now my questions:
1. What exactly means “from 0.0.0.0”? More general: source <ip1> from <ip2>? What is ip2? And why 0.0.0.0? I see that this is a broadcast packet from that part: ll header:
2. Why each time the source is different? Isn’t that suspicious?
3. What security issues may exist in this situation?
4. What kind of misconfiguration may cause these messages?
I want to thank for all your answers.
Regards!