[ previous ] [ next ] [ threads ]
 
 From:  anders knudsen <andersbk at gmail dot com>
 To:  m0n0wall at lists dot m0n0 dot ch
 Subject:  Block rule not silent.
 Date:  Sun, 19 Dec 2004 23:08:55 -0700
I've been steadily adding many large known spammer networks to the top
of my firewall rules, blocking them completely...or so I thought.

I have a rule to block 61.0.0.0/8, and not log them, but just today
got these entries. I would have expected these below to be silently
dropped.

It's:
@25 block in quick from 61.0.0.0/8 to any group 200

FYI, my m0n0wall is running in PPPoE mode via a bridged DSL modem.

Any ideas/comments?

TIA,
-anders.

Dec 19 22:50:30 m0n0wall ipmon[72]: 22:50:30.543101 ng0 @0:14 b
61.33.229.133,46199 -> 70.a.b.c,5232 PR tcp len 20 40 -R IN
Dec 19 22:50:31 m0n0wall ipmon[72]: 22:50:30.600027 ng0 @0:14 b
61.33.229.133,46203 -> 70.a.b.c,5232 PR tcp len 20 40 -R IN
Dec 19 22:50:31 m0n0wall ipmon[72]: 22:50:30.601117 ng0 @0:14 b
61.33.229.133,46205 -> 70.a.b.c,5232 PR tcp len 20 40 -R IN
Dec 19 22:50:31 m0n0wall ipmon[72]: 22:50:30.678054 ng0 @0:14 b
61.33.229.133,46209 -> 70.a.b.c,5232 PR tcp len 20 40 -R IN
Dec 19 22:50:31 m0n0wall ipmon[72]: 22:50:30.710077 ng0 @0:14 b
61.33.229.133,46213 -> 70.a.b.c,5232 PR tcp len 20 40 -R IN
Dec 19 22:50:31 m0n0wall ipmon[72]: 22:50:30.803956 ng0 @0:14 b
61.33.229.133,46217 -> 70.a.b.c,5232 PR tcp len 20 40 -R IN
Dec 19 22:50:31 m0n0wall ipmon[72]: 22:50:30.926177 ng0 @0:14 b
61.33.229.133,46221 -> 70.a.b.c,5232 PR tcp len 20 40 -R IN
Dec 19 22:50:31 m0n0wall ipmon[72]: 22:50:31.131117 ng0 @0:14 b
61.33.229.133,46226 -> 70.a.b.c,5232 PR tcp len 20 40 -R IN