Re: [opensuse] Unusual traffic through eth0
- From: Per Jessen <per@xxxxxxxxxxxx>
- Date: Mon, 12 Mar 2012 12:33:13 +0100
Bob Williams wrote:
On 12/03/12 09:54, Per Jessen wrote:
Bob Williams wrote:Really? I do run skype from time to time, and have tried out ekiga, so
Last night, I noticed a regular pattern of blips in gkrellm's eth0
monitor. There were no internet active programs, such as e-mail or
web browser running, so I started Wireshark to see what was
happening.
Apart from the expected chatter between this machine and the router,
the following two lines repeated over and over, and it is continuing
on rebooting the machine this morning:
Source Destination Protocol Info
217.14.132.183 192.168.1.14 SIP Status: 100
Trying (0 bindings)
217.14.132.183 192.168.1.14 SIP Status: 401
Unauthorized (0 bindings)
Is this entirely innocent, or should I contact abuse@Domainmaster
(see below)?
Perhaps not entirely innocent (SIP attempts for VoIP), but I would
have thought your firewall should be blocking such traffic?
maybe the SIP protocol is allowed.
Skype is proprietary, I don't know what ekiga does. SIP is "Session
Initiation Protocol" for standard VoIP. My Asterisk telephone server
is regularly flooded by SIP requests, bordering on a DoS attack.
The only services I have explicitly allowed in YaST Firewall
Configuration are Rsync server, Secure Shell server and xntp server.
I would expect that to mean that the SIP traffic is dropped or rejected..
Maybe check your firewall log.
All the above traffic seems to be one way, in other words, I never see
my machine sending a reply, I am always the destination, never the
source.
Maybe gkrellm is reporting on traffic before the firewall drops it.
--
Per Jessen, Zürich (9.8°C)
--
To unsubscribe, e-mail: opensuse+unsubscribe@xxxxxxxxxxxx
To contact the owner, e-mail: opensuse+owner@xxxxxxxxxxxx
- Follow-Ups:
- Re: [opensuse] Unusual traffic through eth0
- From: Bob Williams
- Re: [opensuse] Unusual traffic through eth0
- References:
- [opensuse] Unusual traffic through eth0
- From: Bob Williams
- Re: [opensuse] Unusual traffic through eth0
- From: Per Jessen
- Re: [opensuse] Unusual traffic through eth0
- From: Bob Williams
- [opensuse] Unusual traffic through eth0
- Prev by Date: Re: [opensuse] Unusual traffic through eth0
- Next by Date: [opensuse] Re: Ridiculous bug in zypper
- Previous by thread: Re: [opensuse] Unusual traffic through eth0
- Next by thread: Re: [opensuse] Unusual traffic through eth0
- Index(es):
Relevant Pages
|