[prev in list] [next in list] [prev in thread] [next in thread] 

List:       suse-linux-e
Subject:    Re: [SLE] SFW2-INext-DROP-DEFLT-INV in /var/log/warn?
From:       Darryl Gregorash <raven () accesscomm ! ca>
Date:       2005-12-03 17:21:31
Message-ID: 4391D41B.1060407 () accesscomm ! ca
[Download RAW message or body]

On 11/29/2005 06:04 PM, Steven T. Hatton wrote:
>SFW2-INext-DROP-DEFLT-INV What does this mean?  I'm having trouble 
>transferring data from a site which I believe is very fast.  I've noticed 
>there are messages in the warn log containing the string shown above and also 
>the IP address of the sever in question.
It means that some invalid packets received on the external device were
dropped by the firewall, and that is the default behaviour for invalid
packets on that device.

I have no idea why a packet would be considered "invalid", but the
firewall rule(s) for this should be reached only after all other
possibilities have been exhausted. Maybe it is a malformed tcp header or
something.

-- 
Check the headers for your unsubscription address
For additional commands send e-mail to suse-linux-e-help@suse.com
Also check the archives at http://lists.suse.com
Please read the FAQs: suse-linux-e-faq@suse.com


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic