Hello,
I have a firewall configured to have a table with IPs that should be blocked and dropped.
But when I use tcptrack, I can see all the connections:
and a lot more.
This should be dropped, but even with the rules I have my server sends the SYN.
The rule that seems not to be working is:
Shouldn't it drop the connections from the IPs, as soon as they connect to the server?
I don't know if I am doing something wrong.
I have a firewall configured to have a table with IPs that should be blocked and dropped.
But when I use tcptrack, I can see all the connections:
Code:
189.41.221.78:57042 67.43.230.251:7004 SYN_SENT 14s 0 B/s
189.60.153.48:64299 67.43.230.251:7004 SYN_SENT 3s 0 B/s
189.41.221.78:57091 67.43.230.251:7004 SYN_SENT 8s 0 B/s
189.60.153.48:64311 67.43.230.251:7004 SYN_SENT 1s 0 B/s
189.41.221.78:57013 67.43.230.251:7004 SYN_SENT 26s 0 B/s
189.60.153.48:64274 67.43.230.251:7004 SYN_SENT 12s 0 B/s
and a lot more.
This should be dropped, but even with the rules I have my server sends the SYN.
The rule that seems not to be working is:
Code:
block drop in quick on $externa from <vlwc>
Shouldn't it drop the connections from the IPs, as soon as they connect to the server?
I don't know if I am doing something wrong.