Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

"I got a question for ya. Ya got a minute?" -- two programmers passing in the hall


computers / alt.os.linux.mageia / Re: Strange REJECT messages in dmesg

SubjectAuthor
* Strange REJECT messages in dmesgWilliam Unruh
+* Re: Strange REJECT messages in dmesgBit Twister
|`- Re: Strange REJECT messages in dmesgWilliam Unruh
`- Re: Strange REJECT messages in dmesgDavid W. Hodgins

1
Strange REJECT messages in dmesg

<t2553u$eka$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=4585&group=alt.os.linux.mageia#4585

  copy link   Newsgroups: alt.os.linux.mageia
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: unr...@invalid.ca (William Unruh)
Newsgroups: alt.os.linux.mageia
Subject: Strange REJECT messages in dmesg
Date: Thu, 31 Mar 2022 21:06:07 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 15
Message-ID: <t2553u$eka$1@dont-email.me>
Injection-Date: Thu, 31 Mar 2022 21:06:07 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="e2370f73e9a2e7be915d9f4a7346a196";
logging-data="14986"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19UEu7w3NTJwIZwUWUsevrO"
User-Agent: slrn/1.0.3 (Linux)
Cancel-Lock: sha1:CzyOTf6x0vhyOI64T/mV2egLBlE=
 by: William Unruh - Thu, 31 Mar 2022 21:06 UTC

I am getting a whole bunch of messages in dmeg which look like the
following

Shorewall:sshc-fw:REJECT:IN=enp4s0 OUT= MAC=f8:32:e4:70:14:5b:f4:4e:05:08:4b:00:08:00 SRC=101.227.98.81 DST=142.103.234.23 LEN=52 TOS=0x00 PREC=0x00 TTL=44 ID=50529 DF PROTO=ICMP TYPE=8 CODE=0 ID=18477 SEQ=22560

sshc is a "host" entry in /etc/shorewall/hosts. It starts like
sshc enp+:14.208.0.0/12,31.162.0.0/18....

I assume sshc-fw is a comment that it is the sshc firewall rule that is
producing there Rejects, but there is not sshc firewall rule which says
to REJECT ICMP packets.And a REJECT would be wrong anyway since it would
be a reply to the remote machine.

The only ICMP rule I had was an ACCEPT rule for a local range of
addresses.

Re: Strange REJECT messages in dmesg

<slrnt4c7vr.9dgm.BitTwister@wb.home.test>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=4586&group=alt.os.linux.mageia#4586

  copy link   Newsgroups: alt.os.linux.mageia
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: BitTwis...@mouse-potato.com (Bit Twister)
Newsgroups: alt.os.linux.mageia
Subject: Re: Strange REJECT messages in dmesg
Date: Thu, 31 Mar 2022 16:41:13 -0500
Organization: A noiseless patient Spider
Lines: 22
Message-ID: <slrnt4c7vr.9dgm.BitTwister@wb.home.test>
References: <t2553u$eka$1@dont-email.me>
Injection-Info: reader02.eternal-september.org; posting-host="2261293a0c8017f6c5c05bc10ee970aa";
logging-data="30514"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/Qbli7RjNA1StQTlXAqs1RoHXDaYv5W/4="
User-Agent: slrn/pre1.0.4-6 (Linux)
Cancel-Lock: sha1:NDMkuxXNLS1YG4YinDwRnKFilRU=
 by: Bit Twister - Thu, 31 Mar 2022 21:41 UTC

On Thu, 31 Mar 2022 21:06:07 -0000 (UTC), William Unruh wrote:
> I am getting a whole bunch of messages in dmeg which look like the
> following
>
> Shorewall:sshc-fw:REJECT:IN=enp4s0 OUT= MAC=f8:32:e4:70:14:5b:f4:4e:05:08:4b:00:08:00 SRC=101.227.98.81 DST=142.103.234.23 LEN=52 TOS=0x00 PREC=0x00 TTL=44 ID=50529 DF PROTO=ICMP TYPE=8 CODE=0 ID=18477 SEQ=22560
>
> sshc is a "host" entry in /etc/shorewall/hosts. It starts like
> sshc enp+:14.208.0.0/12,31.162.0.0/18....
>
> I assume sshc-fw is a comment that it is the sshc firewall rule that is
> producing there Rejects, but there is not sshc firewall rule which says
> to REJECT ICMP packets.And a REJECT would be wrong anyway since it would
> be a reply to the remote machine.
>
> The only ICMP rule I had was an ACCEPT rule for a local range of
> addresses.

I do not use the /hosts file and never seen :sshc-fw:

Keep in mind that shorewall runs through the rules file and if no rule
is found for the connection then the default option is taken which I think
is Drop in my setup.

Re: Strange REJECT messages in dmesg

<op.1jwzvl0sa3w0dxdave@hodgins.homeip.net>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=4587&group=alt.os.linux.mageia#4587

  copy link   Newsgroups: alt.os.linux.mageia
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: dwhodg...@nomail.afraid.org (David W. Hodgins)
Newsgroups: alt.os.linux.mageia
Subject: Re: Strange REJECT messages in dmesg
Date: Thu, 31 Mar 2022 17:41:35 -0400
Organization: A noiseless patient Spider
Lines: 49
Message-ID: <op.1jwzvl0sa3w0dxdave@hodgins.homeip.net>
References: <t2553u$eka$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed; delsp=yes
Content-Transfer-Encoding: 8bit
Injection-Info: reader02.eternal-september.org; posting-host="dad388fee24fd1a745a989d86ddde455";
logging-data="4583"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19VQB2Csi2i1tH8vQiPksUYFgcEcRPT4mI="
User-Agent: Opera Mail/12.16 (Linux)
Cancel-Lock: sha1:nea8wrbzJIdosfSBr1kfR34tPKg=
 by: David W. Hodgins - Thu, 31 Mar 2022 21:41 UTC

On Thu, 31 Mar 2022 17:06:07 -0400, William Unruh <unruh@invalid.ca> wrote:

> I am getting a whole bunch of messages in dmeg which look like the
> following
>
> Shorewall:sshc-fw:REJECT:IN=enp4s0 OUT= MAC=f8:32:e4:70:14:5b:f4:4e:05:08:4b:00:08:00 SRC=101.227.98.81 DST=142.103.234.23 LEN=52 TOS=0x00 PREC=0x00 TTL=44 ID=50529 DF PROTO=ICMP TYPE=8 CODE=0 ID=18477 SEQ=22560
>
> sshc is a "host" entry in /etc/shorewall/hosts. It starts like
> sshc enp+:14.208.0.0/12,31.162.0.0/18....
>
> I assume sshc-fw is a comment that it is the sshc firewall rule that is
> producing there Rejects, but there is not sshc firewall rule which says
> to REJECT ICMP packets.And a REJECT would be wrong anyway since it would
> be a reply to the remote machine.
>
> The only ICMP rule I had was an ACCEPT rule for a local range of
> addresses.

From "man shorewall-hosts"
Most simple setups don't need to (should not) place anything in this file.

There are also two warnings in the man page.
I've added nothing to /etc/shorewall/hosts on any system I control.

PROTO=ICMP TYPE=8 = Echo (aka ping).
SRC=101.227.98.81 shows it's coming from chinatelecom.cn

On my systems, I accept all icmp traffic. See
https://blog.paessler.com/disabling-icmp-and-snmp-wont-increase-security-but-will-impact-network-monitoring

By blocking icmp traffic, packets being sent may be rejected due to being to large
for some hop along it's path, but your system will not know it. Same if a packet
get's rejected somewhere along it's path due to a timeout.

Having outgoing packets getting dropped without your system getting the notifications
means your system will eventually retry the packet, after a longer than needed delay.
It will slow down the transfer rate of data.

In /etc/shorewall/policy, Mageia systems normally have a line with ...
net all DROP

Clearly, the changes being made to shorewall configuration has caused that to be
bypassed and fall through to the next line which has ...
all all REJECT info

To avoid ping floods, block icmp type 8 at the router, but leave the other icmp
types open.

Regards, Dave Hodgins

Re: Strange REJECT messages in dmesg

<t25df1$fv7$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=4590&group=alt.os.linux.mageia#4590

  copy link   Newsgroups: alt.os.linux.mageia
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: unr...@invalid.ca (William Unruh)
Newsgroups: alt.os.linux.mageia
Subject: Re: Strange REJECT messages in dmesg
Date: Thu, 31 Mar 2022 23:28:33 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 54
Message-ID: <t25df1$fv7$1@dont-email.me>
References: <t2553u$eka$1@dont-email.me>
<slrnt4c7vr.9dgm.BitTwister@wb.home.test>
Injection-Date: Thu, 31 Mar 2022 23:28:33 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="0c2c8ce52b49b9e3f02297f8c3c8c4ee";
logging-data="16359"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19ZYRejCK451ls5SMOOLp1g"
User-Agent: slrn/1.0.3 (Linux)
Cancel-Lock: sha1:OgvNCnXBsnwf3KzKK69QUKxZxnE=
 by: William Unruh - Thu, 31 Mar 2022 23:28 UTC

On 2022-03-31, Bit Twister <BitTwister@mouse-potato.com> wrote:
> On Thu, 31 Mar 2022 21:06:07 -0000 (UTC), William Unruh wrote:
>> I am getting a whole bunch of messages in dmeg which look like the
>> following
>>
>> Shorewall:sshc-fw:REJECT:IN=enp4s0 OUT= MAC=f8:32:e4:70:14:5b:f4:4e:05:08:4b:00:08:00 SRC=101.227.98.81 DST=142.103.234.23 LEN=52 TOS=0x00 PREC=0x00 TTL=44 ID=50529 DF PROTO=ICMP TYPE=8 CODE=0 ID=18477 SEQ=22560
>>
>> sshc is a "host" entry in /etc/shorewall/hosts. It starts like
>> sshc enp+:14.208.0.0/12,31.162.0.0/18....
>>
>> I assume sshc-fw is a comment that it is the sshc firewall rule that is
>> producing there Rejects, but there is not sshc firewall rule which says
>> to REJECT ICMP packets.And a REJECT would be wrong anyway since it would
>> be a reply to the remote machine.
>>
>> The only ICMP rule I had was an ACCEPT rule for a local range of
>> addresses.
>
> I do not use the /hosts file and never seen :sshc-fw:

I assume that designates a rule for packets from the sshc zone(shorewall/zone)
and IP addresses (shorewall/hosts) to the firewall.
The sshc zone is a set of subnets which have been shown to generate a
lot of ssh attacks ( as seen in auth.log failed login attempts.) which I
permanantly ban instead of temporarily in the sshd zone with hosts
listed in ipset.

>
> Keep in mind that shorewall runs through the rules file and if no rule
> is found for the connection then the default option is taken which I think
> is Drop in my setup.

Well, I have various groups of hosts that are controlled differently.
Thus my immediate subnet I want to control differently, and from my
reading it seemed that that was done via the hosts file.
Thus my immediate work environment I want to be pretty liberal in what
ports it accepts. My home network, is more liberal than the net but
somewhat more tightly controlled than my work subnet. I use ipset to
define a bunch of Ip adresses that are not allowed to connect to the ssh
ports (set up from too many bad attempts in /var/log/auth.log), but
since I travel a lot, I do not want to ban everything or I could not log
in from outside when I am in Ulan Bator say trying to log in.
Ie each zone with their hosts in that zone (defined in the host file) is
treated differently by the firewall.
From my, admittedly tenuous, understanding, that is what Zones and Hosts
is for.

But for some reason, the sshc ( which are lists of IP groups of
addresses, say 111.12.0.0/14-- which would be expanded into about
300000 addresses if I put them into an ipset list) zone is being treated
differently, and is REJECTing the connection and thus sending back a
rejection message, letting the other side know I exist, rather than DROPing it.
They seem all to be ICMP type 8 requests.

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor