Hi everyone
my firewall have s..ome problem, did anyone help me ? 建材
i acce.pt squid read 80 port f.rom internet.投资
but in my log file, i found some (.not all) packet from Source port 80 and. iptables reject them?. '健康
why
---.------------------学习
Rhel3
[root@mail root]# rpm. -q. iptables虚拟主机
iptables-1..2.8-12 乙肝
--------.---------------.
---.-----------.-----------------------.
My iptables settin.g.
--------.---------------------------.----.
'Chain .RH-Firewal.l-1-INPUT (2 references) 汽车
pkts byte.s target prot opt in out. source . destination.
1807K 150M ACCEPT all -- lo. * 0.0..0.0/0 . 0.0.0.0/0 健康
40M 6735M ACCEPT . all .-- * * 0.0.0.0/0 0.0.0.0/0 .state RELATED,ESTABLISHED电脑
839 278K ACCEPT udp --. eth1 * 0.0.0.0/0 0.0.0.0/0 state N.E.W udp spt:53.
6 240 ACCEP.T tcp -- eth.1 * 0.0.0.0/0 0.0.0.0./0 state NEW tcp spt:1521( 游戏 )
929 40074 ACCEPT tcp -- eth1 .* 0.0.0.0/0 0.0..0.0/0 . state NEW tcp spt:80 婚庆
. 32 1280 ACCEPT tcp -- eth1 * 0.0.0.0/0 0.0.0.0/0 sta.t.e NEW tcp spt:443虚拟主机
0 0 REJECT udp -- eth1 * . . 0.0.0.0/0 0.0.0.0/0 . state NEW udp. spt:67 reject-with icmp-port-unreachable电脑
0 . 0 REJECT udp -- eth1 * 0.0.0.0/0 . 0.0.0.0/0 stat.e NEW udp spt:68 reject-with icmp-port-unreachab.le.
1680 67200 .LOG all -- . eth1 * . 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 0 prefix `'FW-eth1''.
1680 6720.0 REJECT all -- eth1 * 0.0.0.0/0 0.0.0.0/0 . reject-with icmp-host.-prohibited教育
---------------------.---- 建材
--------------------.------.----- 印刷
[r.oot@mail root]# dmesg 鲜花
5 LEN=40 TOS=0x00 PRE.C=0x00 TTL=254 ID=0 DF PROTO=TCP SPT=80 DPT=42195 WINDO.W.=0 RES=0x00 RST URGP=0教育
'FW-eth1'IN=eth1 OUT= MAC=00:0d.:60:1a:1f:2b:0.0:50.:7f.:06:d6:1a:08:00 SRC=61.172.201.224 DST=192.168.1.5 LEN=40 TOS=0x00 PREC=0x00 TTL=254 ID=0 DF PROTO=TCP SPT=80 DPT=42183 WINDOW=0 RES=0x00 RST UR.GP=0 杀毒
'FW-eth1'.IN=eth1 OUT= MAC=0.0:0d:60:1a:1f:2b:00:50:7f:06:d6:1a:08:00 SRC=216.239.63.91 DST=192.168.1.5 LEN=40 TOS=0x0.0 PREC=0x00 TTL=254 ID=0 DF PROTO=TC.P SPT=80 DPT=42.194 WINDOW=0 RES=0x00 RST URGP=0.
'FW-eth1'IN=eth1 OUT= MAC=00:0d:60:1a:1f:2b:00:50:7f:06:d6:1a:08:00 SRC=216.239.63.93 DST=192.168.1.5 LEN.=40 TOS.=0x00 PREC=0x00 TTL=254 ID=0 DF PROTO=TCP SPT=80 .DPT=42193 WINDOW=0 RES.=0x00 RS.T URGP=0外贸
'.FW-eth1'IN=eth1 OUT= MAC=00:0d:60:1a:1f:2b:00:50.:7f:06:d6:1a:08:00 S.RC=2.16.239.63.91 DST=192.16.8.1.5 LEN=40 TOS=0x00 PREC=0x00 TTL=254 ID=0 DF PROTO=TCP SPT=80 DPT=42192 WINDOW=0 RES=0x00 RST URGP=0 外汇
'FW-eth1'IN.=eth1 OUT= MAC=00:0d:60:1a:1f:2b:00:50:7f:06:d6:1a:08:00 SRC=216.239.63.93 DST=1.92.168.1.5 LEN=40 .TOS=0x00. PREC=0x00 TTL=254 ID=0 DF PROTO=TCP SPT=80 DPT=42191 WINDOW=0 RES=.0x00 RST URGP=0投资
'FW-eth1'IN=eth.1 OUT.= MAC=00:0d:60:1a:1f:2b:00:50:7f:06:d6:1a:08:00 SRC=216..239.63.93 DST=192.168.1.5 LEN=40 TOS=0x00 .PREC=0x00 TTL=254 ID=0 DF .PROTO=TCP SPT=80 DPT=42125 WINDOW=0 RES=0x00 RST URGP=0.
'FW-eth1'IN=eth1 OUT= MAC=00:0d:60:1a:1f.:2b:00:50:7f:06:d6:.1a:08:00. SRC=216.239.63.91 DST=192.168.1.5 LEN=40 TOS=0x00 P.RE.C=0x00 TTL=254 ID=0 PROTO=TCP SPT=80 DPT=42017 WINDOW=0 RES=0x00 RST URGP=0 汽车
'-.-----------------.