[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-users] RaQ4 - Help with Portsentry on Cobalt RaQ4r



Hi,

I'm having some problems setting up Logcheck and Portsentry on my Cobalt RaQ4r. The following log is emailed to me:


Feb 20 10:06:06 www portsentry[15570]: attackalert: Connect from host: 192.168.1.1/192.168.1.1 to UDP port: 69 Feb 20 10:06:06 www portsentry[15570]: attackalert: Host: 192.168.1.1 is already blocked. Ignoring Feb 20 10:06:10 www portsentry[15570]: attackalert: Connect from host: 192.168.1.1/192.168.1.1 to UDP port: 69 Feb 20 10:06:10 www portsentry[15570]: attackalert: Host: 192.168.1.1 is already blocked. Ignoring


...and so on, every 5 minutes, througout the day.

It seems to me that something is happening on the Cobalt RaQ that is sending UDP packets to Port 69, but I don't know what this is. I know that tftp operates on this port, but I don't know if the RaQ has this running or why.

Also, can anyone explain the following log entry, and how to solve it?

Feb 20 10:15:03 www sendmail[1153]: NOQUEUE: localhost [127.0.0.1] did not issue MAIL/EXPN/VRFY/ETRN during connection to MTA

This appears every 15 minutes.

Many thanks

Tony
_________________________________________________________________________
Get Your Private, Free E-mail from MSN Hotmail at http://www.hotmail.com.