Brandon Holland wrote:
> 20:18:33.523088 vr0 @0:13 b 220.127.116.11,3620 -> 172.22.1.22,110 PR tcp
> len 20 44 -AR IN
> What exactly does that mean?
> At the time above, out the interface vr0, via the rule number? (What is
> the 0:13) a packet was blocked from ip/port above to ip/port above.
> Protocol tcp, len 20? What does that mean? 44? -AR?
It means an *incoming* TCP packet on vr0 from 18.104.22.168 port 3620 to
172.22.1.22 port 110 with a header length of 20 bytes and a total length
of 44 bytes and with the TCP flags ACK and RST set was blocked by rule
13 in group 0.