How to read "Firewall: *TCP_IN Blocked*" message?

  • Thread starter Thread starter postcd
  • Start date Start date
P

postcd

Hello,

FTP users are getting blocked false by firewall (config server firewall), i need to learn what firewall rule triggering this block, so from /var/log/messsages i see following. I want to ask how to read it and get the info on which value tot weak?

Quote:
...
May 26 03:16:40 host1 kernel: Firewall: *TCP_IN Blocked* IN=venet0 OUT= MAC= SRC=190.140.142.24 DST=107.182.133.29 LEN=52 TOS=0x00 PREC=0x00 TTL=106 ID=9289 DF PROTO=TCP SPT=60500 DPT=1880 WINDOW=65535 RES=0x00 SYN URGP=0
May 26 01:49:50 host1 kernel: Firewall: *TCP_IN Blocked* IN=venet0 OUT= MAC= SRC=190.140.142.24 DST=107.182.133.29 LEN=52 TOS=0x00 PREC=0x00 TTL=106 ID=8199 DF PROTO=TCP SPT=58858 DPT=17411 WINDOW=65535 RES=0x00 SYN URGP=0
...

Continue reading...
 
Back
Top