gb-users mailing list archive
<-- Chronological -->
Extended
<-- Thread -->

strange logs - revisited

To: <gb-users_at_gta_dot_com>
Subject: strange logs - revisited
From: "Jon Thiele" <jthiele_at_plexnet_dot_com>
Date: Tue, 14 Mar 2000 23:21:50 -0500

I have the same problem that "michael" mentioned in a mail message to this
list on Wed, 5 Jan 2000 - he was receiving multiple messages that looked
like:

Jan 5 22:32:43  FILTER: remote access filter blocks: UDP bcast fxp0
[199.245.180.13/1015] ->[255.255.255.255/1015] l=148

I currently average about 40 to 50 per minute of exactly the same type of
message.

I modified the rule to say "Deny ANY UDP nolog from "ANY_IP" to "ANY_IP" 9
67 68 137 138 139 148 161 513" and saved my configuration but I still get
these messages.

In a reply to Michael's message, Joe Biniskiewicz suggested that "The
solution is to set your alarm thresholds high enough that you don't get
email and pager messages regarding these broadcasts, and then otherwise
ignore them."  However, I'd really don't want to see them and I thought my
rule would solve this problem.

Anyone see the reason I'm still logging these broadcast messages???


Thanx.


<Prev in Thread] Current Thread [Next in Thread>

Global Technology Associates, Inc