ipchains: icmp "port" 8 to "port" 0

ipchains: icmp "port" 8 to "port" 0

Post by Mark Olber » Tue, 06 Feb 2001 03:27:03



I run a firewall using ipchains on linux-2.2.18. My system log files
seem to contain a lot of firewall rejects for icmp connections from
various ip addresses, all referring to icmp connections from "port" 8
to "port" 0.

Can someone point me to a reference on what these are? And tell me
whether I should be concerned about them or not?

- Mark

 
 
 

ipchains: icmp "port" 8 to "port" 0

Post by W1.. » Tue, 06 Feb 2001 03:36:57



> I run a firewall using ipchains on linux-2.2.18. My system log files
> seem to contain a lot of firewall rejects for icmp connections from
> various ip addresses, all referring to icmp connections from "port" 8
> to "port" 0.

Those Ports are no real ports but the used ICMP Types. Just look in the man
page of ichains:

              The source may include a port specification or ICMP
              type.  This can either be a service  name,  a  port
              number,  a  numeric  ICMP  type, or one of the ICMP
              type names shown by the command
              ipchains -h icmp Note that many of these ICMP names
              refer to both a type and code, meaning that an ICMP
              code after the -d flag is illegal.  In the rest  of
              this paragraph, a port means either a port specifi-
              cation or an ICMP type.

Quote:> Can someone point me to a reference on what these are? And tell me
> whether I should be concerned about them or not?

It is a ping, you most likely dont need to be concerned and you should read
the ipchains howto anyway.

Greetings
Bernd

 
 
 

ipchains: icmp "port" 8 to "port" 0

Post by Ian Jone » Tue, 06 Feb 2001 04:00:05


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Quote:> I run a firewall using ipchains on linux-2.2.18. My system log
> files seem to contain a lot of firewall rejects for icmp
> connections from various ip addresses, all referring to icmp
> connections from "port" 8 to "port" 0.

> Can someone point me to a reference on what these are? And tell me
> whether I should be concerned about them or not?

You should have a loog at Manfred's pages:
http://logi.cc/linux/ipchains-log-format.html

-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 6.5.8 for non-commercial use <http://www.pgp.com>
Comment: Making the world safe for geeks.

iQA/AwUBOn2lRMAVSpfzXItKEQJ3fwCgzwoHzNfFSfRKO1pcCWtf5xsaBtoAoL+B
N9dlyo4d7cPuAgM8HpciJZzE
=2n0+
-----END PGP SIGNATURE-----