LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-26-2005, 02:58 AM   #1
apache
Member
 
Registered: Jun 2004
Posts: 37

Rep: Reputation: 15
Why iptables logs is troubling me..so much?


Hi Geeks,
My machine was hanged up in the morning...and lots of iptables logs were started pouring on screen...I was even unable to login..

The messages were something like that:
10.0.1.255 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=22244 PROTO=UDP SPT=137 DPT=137 LEN=58
Jul 26 12:17:51 mail1 kernel: IPTABLES UDP-IN: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:0d:61:2f:06:19:08:00 SRC=10.0.1.49 DST=10.0.1.255 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=16750 PROTO=UDP SPT=137 DPT=137 LEN=58
Jul 26 12:17:51 mail1 kernel: IPTABLES UDP-IN: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:0d:61:2b:b5:0b:08:00 SRC=10.0.1.111 DST=10.0.1.255 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=19591 PROTO=UDP SPT=137 DPT=137 LEN=58
Jul 26 12:17:51 mail1 kernel: IPTABLES UDP-IN: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:0d:61:2f:06:19:08:00 SRC=10.0.1.49 DST=10.0.1.255 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=16757 PROTO=UDP SPT=137 DPT=137 LEN=58
Jul 26 12:17:51 mail1 kernel: IPTABLES UDP-IN: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:11:11:2f:9b:44:08:00 SRC=10.0.1.71 DST=10.0.1.255 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=49919 PROTO=UDP SPT=137 DPT=137 LEN=58

Can anyone tell me is it h/w issue or kernel..?
And if h/w is it with n/w card...?

Thanks..
 
Old 07-26-2005, 03:00 AM   #2
apache
Member
 
Registered: Jun 2004
Posts: 37

Original Poster
Rep: Reputation: 15
Oh..
I forgot the details..

It is Intel Xeon 4Processor...6GB RAM 350GB HD FC3 machine..
n/w card is of
Ethernet controller: Intel Corp. 82544GC Gigabit Ethernet Controller (LOM) (rev 02)
 
Old 07-26-2005, 09:45 AM   #3
tommyr1216
Member
 
Registered: Sep 2004
Location: Pennsylvania
Distribution: Gentoo, Suse, Fedora, Slackware
Posts: 56

Rep: Reputation: 15
Those packets are using port 137, which I believe Windows uses to broadcast netbios name information. If you have Windows machines on your network, your Linux box is seeing those broadcasts and logging them. You are probably seeing these messages because you have a "-j LOG" somewhere in your IPTables rules. The log messages come from netfilter in the kernel, and thus are printed on the console. You can remove the log statements from IPTables or modify your syslog.conf to have kernel messages not go to the console. This should rid you of those messages, although I can't see why this would cause your system to hang.
 
Old 07-26-2005, 05:26 PM   #4
Krugger
Member
 
Registered: Oct 2004
Posts: 229

Rep: Reputation: 30
Maybe got nuked so you computer got really slow as it had to log all the packets coming from your gigabyte card into you log file. And maybe your logfiles got really big and filed your tiny 350Gb disk. Perhaps your are suffering from the too much log problem.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Seperating IPTABLES Logs TheRealDeal Linux - Security 5 02-26-2005 08:51 AM
help me understanding iptables logs ddaas Linux - Security 1 02-23-2005 09:08 AM
iptables logs ddaas Linux - Security 1 01-20-2005 08:26 AM
iptables -creating logs chrisfirestar Linux - Security 5 02-13-2004 07:17 AM
iptables logs and 1 other thing phil1076 Linux - General 5 12-08-2001 07:25 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:52 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration