thedude
September 15th, 2003, 00:58
This is about all I ever see from my OpenBSD firewall behind a router running NAT.
Sep 12 17:59:37.043593 rule -1/3(short): block in on vr0: 192.168.2.7 > 224.0.0.2: igmp leave 224.0.0.251 (DF) [ttl 1]
Sep 12 18:16:57.166877 rule -1/3(short): block in on vr0: 192.168.2.7 > 224.0.0.2: igmp leave 224.0.1.1 (DF) [ttl 1]
Sep 12 18:16:57.631251 rule -1/3(short): block in on vr0: 192.168.2.7 > 224.0.0.2: igmp leave 224.0.0.251 (DF) [ttl 1]
Sep 13 16:27:52.318783 rule -1/3(short): block in on vr0: 192.168.2.7 > 224.0.0.2: igmp leave 224.0.1.1 (DF) [ttl 1]
Sep 14 18:39:46.172048 rule -1/3(short): block in on vr0: 192.168.2.7 > 224.0.0.2: igmp leave 224.0.1.1 (DF) [ttl 1]
Is this just NTP requests? I haven't found much on Google... I apologize if this is a waste of everybody's time. I'm just disappointed I haven't seen any hack attempts in my logs.
Sep 12 17:59:37.043593 rule -1/3(short): block in on vr0: 192.168.2.7 > 224.0.0.2: igmp leave 224.0.0.251 (DF) [ttl 1]
Sep 12 18:16:57.166877 rule -1/3(short): block in on vr0: 192.168.2.7 > 224.0.0.2: igmp leave 224.0.1.1 (DF) [ttl 1]
Sep 12 18:16:57.631251 rule -1/3(short): block in on vr0: 192.168.2.7 > 224.0.0.2: igmp leave 224.0.0.251 (DF) [ttl 1]
Sep 13 16:27:52.318783 rule -1/3(short): block in on vr0: 192.168.2.7 > 224.0.0.2: igmp leave 224.0.1.1 (DF) [ttl 1]
Sep 14 18:39:46.172048 rule -1/3(short): block in on vr0: 192.168.2.7 > 224.0.0.2: igmp leave 224.0.1.1 (DF) [ttl 1]
Is this just NTP requests? I haven't found much on Google... I apologize if this is a waste of everybody's time. I'm just disappointed I haven't seen any hack attempts in my logs.