Dear friends!
Thanks, for your comments.
I attempted is use Arno's firewall script; Although it is quite good,
but it slows down the network. So I have re-written one from scratch and
is working fine.
My script is logging a lot of un-wanted packets as follows:
$ tail /var/log/firwall.log
Nov 18 12:25:57 cto kernel: INPUT: IN=eth1 OUT=
MAC=00:08:74:48:23:bb:00:08:5c:00:00:01:08:00 SRC=59.144.179.92
DST=192.168.1.2 LEN=48 TOS=0x00 PREC=0x00 TTL=126 ID=7816 DF PROTO=TCP
SPT=3335 DPT=135 WINDOW=16384 RES=0x00 SYN URGP=0
Nov 18 12:29:02 cto kernel: INPUT: IN=eth1 OUT=
MAC=00:08:74:48:23:bb:00:08:5c:00:00:01:08:00 SRC=59.144.184.16
DST=192.168.1.2 LEN=64 TOS=0x00 PREC=0x00 TTL=46 ID=15456 DF PROTO=TCP
SPT=4408 DPT=135 WINDOW=53760 RES=0x00 SYN URGP=0
Nov 18 12:29:05 cto kernel: INPUT: IN=eth1 OUT=
MAC=00:08:74:48:23:bb:00:08:5c:00:00:01:08:00 SRC=59.144.184.16
DST=192.168.1.2 LEN=64 TOS=0x00 PREC=0x00 TTL=46 ID=15833 DF PROTO=TCP
SPT=4408 DPT=135 WINDOW=53760 RES=0x00 SYN URGP=0
Nov 18 12:29:19 cto kernel: INPUT: IN=eth1 OUT=
MAC=00:08:74:48:23:bb:00:08:5c:00:00:01:08:00 SRC=204.16.210.120
DST=192.168.1.2 LEN=434 TOS=0x00 PREC=0x00 TTL=48 ID=0 DF PROTO=UDP
SPT=34701 DPT=1026 LEN=414
Nov 18 12:29:19 cto kernel: INPUT: IN=eth1 OUT=
MAC=00:08:74:48:23:bb:00:08:5c:00:00:01:08:00 SRC=204.16.210.120
DST=192.168.1.2 LEN=434 TOS=0x00 PREC=0x00 TTL=48 ID=0 DF PROTO=UDP
SPT=34701 DPT=1027 LEN=414
Nov 18 12:29:19 cto kernel: INPUT: IN=eth1 OUT=
MAC=00:08:74:48:23:bb:00:08:5c:00:00:01:08:00 SRC=204.16.210.120
DST=192.168.1.2 LEN=434 TOS=0x00 PREC=0x00 TTL=48 ID=0 DF PROTO=UDP
SPT=34701 DPT=1026 LEN=414
Nov 18 12:30:42 cto kernel: INPUT: IN=eth1 OUT=
MAC=00:08:74:48:23:bb:00:08:5c:00:00:01:08:00 SRC=59.144.254.91
DST=192.168.1.2 LEN=48 TOS=0x00 PREC=0x00 TTL=126 ID=16190 DF PROTO=TCP
SPT=3281 DPT=135 WINDOW=65535 RES=0x00 SYN URGP=0
Nov 18 12:30:45 cto kernel: INPUT: IN=eth1 OUT=
MAC=00:08:74:48:23:bb:00:08:5c:00:00:01:08:00 SRC=59.144.254.91
DST=192.168.1.2 LEN=48 TOS=0x00 PREC=0x00 TTL=126 ID=16603 DF PROTO=TCP
SPT=3281 DPT=135 WINDOW=65535 RES=0x00 SYN URGP=0
Nov 18 12:32:38 cto kernel: INPUT: IN=eth1 OUT=
MAC=00:08:74:48:23:bb:00:08:5c:00:00:01:08:00 SRC=59.144.242.130
DST=192.168.1.2 LEN=60 TOS=0x00 PREC=0x00 TTL=126 ID=60368 PROTO=ICMP
TYPE=8 CODE=0 ID=256 SEQ=45921
Nov 18 12:32:45 cto kernel: INPUT: IN=eth1 OUT=
MAC=00:08:74:48:23:bb:00:08:5c:00:00:01:08:00 SRC=59.144.181.250
DST=192.168.1.2 LEN=64 TOS=0x00 PREC=0x00 TTL=46 ID=58860 DF PROTO=TCP
SPT=1717 DPT=135 WINDOW=53760 RES=0x00 SYN URGP=0
What kind of packets are these?
Is'nt the mac address logged above suspicious?
How do I drop these packets? I don't want to log these any more.
I also see a lot of failed intrusion attempts via ssh, do I need to
report these?
If yes, Is there a tool/script available to analyze iptables and, or
sshd logs which can generate such complaints automagically?
Thanking you in anticipation.
Regards,
--
Dr Balwinder S "bsd" Dheeman Registered Linux User: #229709
Anu's Linux@HOME Machines: #168573, 170593, 259192
Chandigarh, UT, 160062, India Distros: Ubuntu, Fedora, Knoppix
Home:
http://cto.homelinux.net/~bsd/ Visit:
http://counter.li.org/