LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-13-2009, 07:35 PM   #1
Toadman
Member
 
Registered: Aug 2002
Location: Copperas Cove, Texas
Distribution: Ubuntu 20.04 LTS
Posts: 304

Rep: Reputation: 21
Opening port for ntp


A week or so ago after updating to Mandriva 2009.1 I'd forgotten to allow port 123 in shorewall and was getting massive amounts of firewall hits in my syslog. I corrected that and have had no problems until today when all of a sudden I'm seeing this again:

May 13 18:00:05 localhost klogd: Shorewall:net2fwROP:IN=eth0 OUT= MAC=00:0f:ea:33:8f:ef:00:13:49:6e:55:07:08:00 SRC=207.171.30.106 DST=192.168.2.2 LEN=76 TOS=0x00 PREC=0x00 TTL=50 ID=2711 DF PROTO=UDP SPT=123 DPT=59380 LEN=56
May 13 18:00:28 localhost klogd: Shorewall:net2fwROP:IN=eth0 OUT= MAC=00:0f:ea:33:8f:ef:00:13:49:6e:55:07:08:00 SRC=66.96.99.10 DST=192.168.2.2 LEN=76 TOS=0x00 PREC=0x00 TTL=50 ID=32831 PROTO=UDP SPT=123 DPT=59380 LEN=56
May 13 18:00:41 localhost klogd: Shorewall:net2fwROP:IN=eth0 OUT= MAC=00:0f:ea:33:8f:ef:00:13:49:6e:55:07:08:00 SRC=208.38.65.37

This goes through all the ntp servers I'm trying to connect for time sync. I checked my firewall setup and port 123/udp is allowed. Running netstat -lnptu, shows among other ports:

udp 0 0 127.0.0.1:123 0.0.0.0:* 3581/ntpd
udp 0 0 0.0.0.0:123 0.0.0.0:* 3581/ntpd
udp 0 0 0.0.0.0:50172 0.0.0.0:*

I've seen no issues since the 8th until this morning at 6am when this all started again. Has something gotten mis-configured somehow all by itself?

Thanks
Chris

Last edited by Toadman; 05-13-2009 at 07:40 PM.
 
Old 05-14-2009, 01:50 PM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
what does your iptables ruleset look like?
 
Old 05-14-2009, 05:15 PM   #3
Toadman
Member
 
Registered: Aug 2002
Location: Copperas Cove, Texas
Distribution: Ubuntu 20.04 LTS
Posts: 304

Original Poster
Rep: Reputation: 21
It was my error, I had port 123/udp open but not 123/tcp. Odd too since it was working up until yesterday. Thanks for the reply.

Chris
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
ntp drift file in /etc/ntp instead of /var/lib/ntp - suggestion for a patch in Slack niels.horn Slackware 16 05-07-2009 07:35 PM
Why port not opening prashanlk Linux - Networking 1 01-16-2008 02:11 AM
ntp port blocked - how to set date automatically unkie888 Linux - General 4 11-06-2007 05:57 AM
Opening Port steve007 Linux - Newbie 5 07-23-2005 01:05 PM
opening a port Robin01 Linux - General 3 11-17-2004 10:40 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:16 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration