I am getting entries like this in my log: Dec 2 12:00:42 malakili Shorewall:net2fw:ACCEPT: IN=ppp0 OUT= MAC=c0:29:c0:00:00:00:00:11:00:00:00:00:00:00:00:00:00:00:00:01:00:00:00 :00:00:00:00:30:18:00:00:00:00:00:00:01:15:00:00:30:18:00:00:00:00:00:00 :00:20:10:c1:00:20:10:c1:00:00:00:00:00:00:00:00:00:00:00:00:a8:40:7e:c1 :a8:40:7e:c1:00:00:00:00:80:45:00:00:3c:47:a9:40:00:38:06:63:da:42:cf:c7 :22:40:e7:4c:60:f7:14:03:78:92:08:9e:a8:00:00:00:00:a0:02:80:00:54:d0:00 :00:02:04:05:ac:01:03:03:00:01:01:08:0a:f2:a8:c1:1f:00:00:00:00:40:7e:c1 :00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00 :00:00:00:00:00:00:00:00:00 SRC=66.207.199.34 DST=64.231.76.96 LEN=60 TOS=00 PREC=0x00 TTL=56 ID=18345 DF PROTO=TCP SPT=63252 DPT=888 SEQ=2450038440 ACK=0 WINDOW=32768 SYN URGP=0 What''s with the huge MAC address? This seems to have started when I switched to using ulogd (version 1.02). Shorewall is version 1.4.7c (from Debian package), BTW. Thanks! - Colin p.s. I''m not on the mailing list, so copy me personally on any replies, please.
On Tue, 2003-12-02 at 09:08, Faxbox wrote:> I am getting entries like this in my log: > > Dec 2 12:00:42 malakili Shorewall:net2fw:ACCEPT: IN=ppp0 OUT= > MAC=c0:29:c0:00:00:00:00:11:00:00:00:00:00:00:00:00:00:00:00:01:00:00:00 > :00:00:00:00:30:18:00:00:00:00:00:00:01:15:00:00:30:18:00:00:00:00:00:00 > :00:20:10:c1:00:20:10:c1:00:00:00:00:00:00:00:00:00:00:00:00:a8:40:7e:c1 > :a8:40:7e:c1:00:00:00:00:80:45:00:00:3c:47:a9:40:00:38:06:63:da:42:cf:c7 > :22:40:e7:4c:60:f7:14:03:78:92:08:9e:a8:00:00:00:00:a0:02:80:00:54:d0:00 > :00:02:04:05:ac:01:03:03:00:01:01:08:0a:f2:a8:c1:1f:00:00:00:00:40:7e:c1 > :00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00 > :00:00:00:00:00:00:00:00:00 SRC=66.207.199.34 DST=64.231.76.96 LEN=60 > TOS=00 PREC=0x00 TTL=56 ID=18345 DF PROTO=TCP SPT=63252 DPT=888 > SEQ=2450038440 ACK=0 WINDOW=32768 SYN URGP=0 > > What''s with the huge MAC address? This seems to have started when I > switched to using ulogd (version 1.02). Shorewall is version 1.4.7c > (from Debian package), BTW.That''s clearly a bug (and not a Shorewall bug) -- I suggest searching the netfilter mailing list archives as I''m sure that I saw this problem mentioned there. -Tom -- Tom Eastep \ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ teastep@shorewall.net
> Tom Eastep wrote: > > Colin Viebrock wrote: > > > >>I''m noticing some weirdness in my ulog files with version 2.0.10. > Here > >>is a portion of the log: > > > > > Output of "shorewall status" as an attachment, please. > > > > Nevermind -- this is just the wierd way that logging with actions works > in 2.0. If you upgrade to 2.2.0 RC4, it will work the way that you > expect it to.Putting the discussion about English spelling aside, thanks. :) I''m using the Debian package of Shorewall, so I will just take your word for it that it will be fixed in 2.2.0 and wait for the .deb. - Colin