Invalid destination address on my firewall logs
Available news archives: comp.lang.tcl - comp.lang.python - comp.security.firewalls - sci.crypt - comp.lang.php - comp.lang.javascript
Google
 
Web news.hping.org


comp.security.firewalls archive

Invalid destination address on my firewall logs

From: <kierankelly@backpacker.com>
Date: Sat Oct 29 2005 - 13:45:37 CEST

Im using a netgear wireless firewall modem router DG832GT and have
Netgear access points WG602v3. My LAN IP addresses are on the
192.168.254.--- range. I'm blocking ports 6346 - 6348 (gnutella et.
al.) in the firewall rules. My access points keep crashing and the logs
from DG832GT are indicating a lot of trafic being blocked with a
address of 1.0.0.0
Here is a sample from the logs:
 Fri, 2005-10-28 23:09:14 - UDP Packet - Source:64.233.240.146,6346
Destination:1.0.0.0,6346 - [gnutella match]

This address is not a valid addres on my network so where is it coming
from? Or how do I trace it and block it?

TIA
Kieran
Received on Mon Nov 21 02:35:03 2005