[SLE] Firewall and port 5353 (mdnsd)

From: Robert Paulsen (robert_at_paulsenonline.net)
Date: 05/29/05

  • Next message: Sid Boyce: "Re: [SLE] Novell: Public Service Announcement"
    To: "suse-linux-e" <suse-linux-e@suse.com>
    Date: Sun, 29 May 2005 08:36:41 -0500
    
    

    Since I have installed 9.3, my /var/log/firewall is loaded with hundreds
    of the following:

    May 29 03:25:40 avalon kernel: SFW2-INext-DROP-DEFLT IN=eth0 OUT= MAC= SRC=192.168.0.31 DST=224.0.0.251 LEN=107 TOS=0x00 PREC=0x00 TTL=255 ID=8 DF PROTO=UDP SPT=5353 DPT=5353 LEN=87

    Looking up port 5353 I see that this is used by the Multicast DNS daemon
    (mdnsd).

    # ps -ef | grep mdnsd
    nobody 6833 1 0 May24 ? 00:00:00 /usr/sbin/mdnsd -f /etc/rendezvous.conf -b

    Is there anything I should do about this? Seems like the system shouldn't
    be configured in a way that the firewall log is swamped with these messages
    but I am not sure if opening up port 5353 in the firewall is a good thing.

    Thanks.

    -- 
    Check the headers for your unsubscription address
    For additional commands send e-mail to suse-linux-e-help@suse.com
    Also check the archives at http://lists.suse.com
    Please read the FAQs: suse-linux-e-faq@suse.com
    

  • Next message: Sid Boyce: "Re: [SLE] Novell: Public Service Announcement"

    Relevant Pages

    • Re: [SLE] Firewall and port 5353 (mdnsd)
      ... > Looking up port 5353 I see that this is used by the Multicast DNS daemon ... > be configured in a way that the firewall log is swamped with these messages ... > but I am not sure if opening up port 5353 in the firewall is a good thing. ...
      (SuSE)
    • Re: trouble creating policy to access port on internal nic?
      ... Make sure this access rule is on top of the firewall policies list. ... I can see that port 6502 is being denied with the ... I created a firewall policy that allowed ports 6502-6503 for tcp (receive ... I get the same Denied - default rule in the firewall log. ...
      (microsoft.public.isa)
    • Re: ZoneAlarm log shows probes *from* 127.0.0.1 ?
      ... > dump,probably windows machines. ... day) and since its a dialup connection, it would be related to howoften ... firewall log, this only happens sometimes... ... Use a port listener,bind it to port 80 on the loopback, play around ...
      (comp.security.firewalls)
    • Re: Allowing all AD traffic to DCs
      ... I am having trouble opening the proper ... ports on all DCs needed for proper functionality of FRS, ... so I checked the firewall log and saw that traffic ... Can anyone give me a complete list of every port that needs to be ...
      (microsoft.public.windows.server.active_directory)
    • Re: cant remote connect to mailman on panther server
      ... from your remote machine, where adminport is 80 or whatever the mailman ... But I don't know for sure that mailman is on port 80 ... But it would appear the firewall log is lying, or else I can't read, or ...
      (uk.comp.sys.mac)