ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    What Are You Doing Right Now

    Water Closet
    time waster
    285
    88.9k
    41.3m
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ?
      A Former User @scottalanmiller
      last edited by

      @scottalanmiller said:

      @thecreativeone91 said:

      Speaking of which I sure get a lot of stuff trying to come in (from the logs) on odd ports from an Nodebb forum looks to be a grove social community about gaming, odd. Since I don't visit it. They get blocked by my firewall though.

      Do you mean the gamrha.us community? What are you getting from there?

      Yep. I cleared my firewall logs but it was trying to connect to my WAN IP on port 8080 I think it was.

      scottalanmillerS 1 Reply Last reply Reply Quote 0
      • scottalanmillerS
        scottalanmiller @A Former User
        last edited by

        @thecreativeone91 said:

        Yep. I cleared my firewall logs but it was trying to connect to my WAN IP on port 8080 I think it was.

        What was trying to connect? It's just a website like this one. What is it doing?

        ? 1 Reply Last reply Reply Quote 0
        • ?
          A Former User @scottalanmiller
          last edited by

          @scottalanmiller said:

          @thecreativeone91 said:

          Yep. I cleared my firewall logs but it was trying to connect to my WAN IP on port 8080 I think it was.

          What was trying to connect? It's just a website like this one. What is it doing?

          Don't know. It's odd since I don't visit the site.

          ulogd[13393]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60003" outitf="eth0" srcmac="00:1a:a0:55:d5:42" srcip="162.242.243.171" proto="6" length="40" tos="0x00" prec="0x00" ttl="64" srcport="80" dstport="55671" tcpflags="ACK FIN"

          1 Reply Last reply Reply Quote 0
          • scottalanmillerS
            scottalanmiller
            last edited by

            Where do you see port 8080?

            1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller
              last edited by

              What makes you think that it is Gamrha.us?

              ? 1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller
                last edited by

                Could that be an aggressive firewall like Untangle that might just be messing with normal web traffic?

                ? 1 Reply Last reply Reply Quote 0
                • ?
                  A Former User @scottalanmiller
                  last edited by

                  @scottalanmiller said:

                  What makes you think that it is Gamrha.us?

                  That's what the IP goes to without the vhosts domain name. Didn't check if anything else was hosted there.

                  scottalanmillerS 1 Reply Last reply Reply Quote 0
                  • ?
                    A Former User @scottalanmiller
                    last edited by

                    @scottalanmiller said:

                    Could that be an aggressive firewall like Untangle that might just be messing with normal web traffic?

                    It's sophos but, it's in the "normal" firewall not the IPS or threat protection.

                    scottalanmillerS 1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @A Former User
                      last edited by

                      @thecreativeone91 said:

                      @scottalanmiller said:

                      What makes you think that it is Gamrha.us?

                      That's what the IP goes to without the vhosts domain name. Didn't check if anything else was hosted there.

                      Oh. Okay, it's not Gamrha.is, it's this forum attempting to talk to you 🙂 That's part of your ML traffic being dropped.

                      1 Reply Last reply Reply Quote 0
                      • scottalanmillerS
                        scottalanmiller @A Former User
                        last edited by

                        @thecreativeone91 said:

                        @scottalanmiller said:

                        Could that be an aggressive firewall like Untangle that might just be messing with normal web traffic?

                        It's sophos but, it's in the "normal" firewall not the IPS or threat protection.

                        Have not had any reports of issues from Sophos users. Any idea what rules is doing that?

                        ? 1 Reply Last reply Reply Quote 0
                        • ?
                          A Former User @scottalanmiller
                          last edited by

                          @scottalanmiller said:

                          Have not had any reports of issues from Sophos users. Any idea what rules is doing that?

                          No specific rule, it just doesn't match an inbound allow rule so it's denied. It looks like it's no properly negotiating the port with the client so it's coming in as a not established connection (meaning the client side didn't start the communication), so it gets Dropped.

                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                          • ?
                            A Former User
                            last edited by

                            What's with people assuming what issues are without checking into it or being willing to actually get real data on the situation. http://community.spiceworks.com/topic/953228-lan-speeds-on-your-network?page=2

                            scottalanmillerS 1 Reply Last reply Reply Quote 0
                            • ?
                              A Former User
                              last edited by

                              Darn. Looks like an Update in Server 2012 R2 killed a Domain Controller..

                              1 Reply Last reply Reply Quote 0
                              • scottalanmillerS
                                scottalanmiller @A Former User
                                last edited by

                                @thecreativeone91 said:

                                What's with people assuming what issues are without checking into it or being willing to actually get real data on the situation. http://community.spiceworks.com/topic/953228-lan-speeds-on-your-network?page=2

                                Very common. If people only know LAN speed, for example, they see that as the problem every time. I see that one a ton. Having issues? Must be your port speed.

                                Really? When was LAN port speed anyone's issue? It can happen, but when does it happen?

                                1 Reply Last reply Reply Quote 0
                                • scottalanmillerS
                                  scottalanmiller @A Former User
                                  last edited by

                                  @thecreativeone91 said:

                                  @scottalanmiller said:

                                  Have not had any reports of issues from Sophos users. Any idea what rules is doing that?

                                  No specific rule, it just doesn't match an inbound allow rule so it's denied. It looks like it's no properly negotiating the port with the client so it's coming in as a not established connection (meaning the client side didn't start the communication), so it gets Dropped.

                                  Would need some investigation. Looks like normal traffic. It's coming from an established port that you are using (80 on remote.) Would need to wireshark it to see if it is NodeBB doing something funky or if it is the Sophos.

                                  1 Reply Last reply Reply Quote 0
                                  • JoyJ
                                    Joy
                                    last edited by

                                    Good morning.
                                    Coffee time here 🙂

                                    1 Reply Last reply Reply Quote 1
                                    • handsofqwertyH
                                      handsofqwerty
                                      last edited by handsofqwerty

                                      Got FiOS connected for internet directly through my router at my parents' house. No more double-NATing for me!

                                      1 Reply Last reply Reply Quote 0
                                      • nadnerBN
                                        nadnerB
                                        last edited by

                                        Well, I made it to work.
                                        Coffee consumption may need to be higher than average today.
                                        We shall see.

                                        1 Reply Last reply Reply Quote 0
                                        • scottalanmillerS
                                          scottalanmiller
                                          last edited by

                                          I should really make coffee too. Got up at six today.

                                          tonyshowoffT 1 Reply Last reply Reply Quote 0
                                          • tonyshowoffT
                                            tonyshowoff @scottalanmiller
                                            last edited by

                                            @scottalanmiller said:

                                            I should really make coffee too. Got up at six today.

                                            I'm drinking tea right now myself, just woke up about an hour ago, took my modafinil and armodafinil mix (half one each pill). In 30 - 45 minutes I'll be ready to code my butt off.

                                            1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 6
                                            • 7
                                            • 8
                                            • 4443
                                            • 4444
                                            • 6 / 4444
                                            • First post
                                              Last post