IN_TCP DROP ... eth0,none
Been running a dedicated server for a while, this is the first time I've seen the following entries in my logs ... is this someone probing my system for an open relay, incipient of a dDos attack or something else? If so, aside from some IP Table Magic and/or blocking the errant IPs outright, what other counter measures would you suggest?
Code:
--------------------- Kernel Begin ------------------------ Dropped 14 packets on interface eth0 From 63.99.230.31 - 10 packets To 12.34.56.77 - 10 packets Service: smtp (tcp/25) (** IN_TCP DROP **,eth0,none) - 10 packets From 66.79.55.14 - 1 packet To 12.34.56.70 - 1 packet Service: 1458 (tcp/1458) (** IN_TCP DROP **,eth0,none) - 1 packet From 81.152.157.182 - 3 packets To 12.34.56.79 - 3 packets Service: smtp (tcp/25) (** IN_TCP DROP **,eth0,none) - 3 packets ---------------------- Kernel End -------------------------