[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-security] Why does PortSentry continue to log ports 137 and 138 even though I've told it not to?



Stephen Rice <support@xxxxxxxxxxxxxxxxxxxxxx> wrote
> Gerald wrote:
> > Dan wrote:
> > > Thanks, but where is this "route" table? I've tried to
> > > "locate" it but couldn't find it?
> > try "man route" or just enter the command "route" (as
root)
>
>
> Gerald, your dedication to the cause of teaching Dan about
the route command
> is admirable :o) Unfortunately the problem is not really
to do with the
> routing, its that the firewall he's using is setting up
ipchains to log
> stuff it's denying.

I thought his problem revolved around the fact that he
removed the rules from ipchains, and still had the log file
entries. I also think that '!' flag in the routing table
will cause the (kernel) log entries even with the firewall
off,
unless you reboot (which clears the table)
or delete the entries from the routing table.
Please, if I have this wrong CORRECT me.
Gerald