Can someone break this down?
Posted: 11 Feb 2013, 16:32
I'm new to my VPS that I've got signed up for and I'm loving it so far. I also like the firewall and how configurable it is and how easy it really is to manage via the interface. There are some small issues that is happening. Some IP addresses are getting temporarily blocked and I'll receive an email letting me know this. I will eventually get around to checking the settings and/or inputting a whitelist when I get the time. The emails I get looks like a foreign language to me. Can someone break this email down and explain what each part is? For example, what is the port(s) that were scanned that caused the temporary block? Here is one of the emails right from my inbox. Thank you!
Time: Mon Feb 11 08:45:15 2013 -0500
IP: 175.180.104.218 (TW/Taiwan/175-180-104-21
Hits: 11
Blocked: Temporary Block
Sample of block hits:
Feb 11 08:44:23 host kernel: Firewall: *UDP_IN Blocked* IN=venet0 OUT= MAC= SRC=175.180.104.218 DST=207.7.86.103 LEN=58 TOS=0x00 PREC=0x00 TTL=111 ID=5076 PROTO=UDP SPT=39329 DPT=5446 LEN=38 Feb 11 08:44:23 host kernel: Firewall: *UDP_IN Blocked* IN=venet0 OUT= MAC= SRC=175.180.104.218 DST=207.7.86.103 LEN=58 TOS=0x00 PREC=0x00 TTL=111 ID=5079 PROTO=UDP SPT=39329 DPT=5446 LEN=38 Feb 11 08:44:23 host kernel: Firewall: *UDP_IN Blocked* IN=venet0 OUT= MAC= SRC=175.180.104.218 DST=207.7.86.103 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=5080 PROTO=UDP SPT=39329 DPT=5446 LEN=28 Feb 11 08:44:26 host kernel: Firewall: *UDP_IN Blocked* IN=venet0 OUT= MAC= SRC=175.180.104.218 DST=207.7.86.103 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=5196 PROTO=UDP SPT=39329 DPT=5446 LEN=28 Feb 11 08:44:32 host kernel: Firewall: *UDP_IN Blocked* IN=venet0 OUT= MAC= SRC=175.180.104.218 DST=207.7.86.103 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=5529 PROTO=UDP SPT=39329 DPT=5446 LEN=28 Feb 11 08:44:44 host kernel: Firewall: *UDP_IN Blocked* IN=venet0 OUT= MAC= SRC=175.180.104.218 DST=207.7.86.103 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=6231 PROTO=UDP SPT=39329 DPT=5446 LEN=28 Feb 11 08:44:52 host kernel: Firewall: *UDP_IN Blocked* IN=venet0 OUT= MAC= SRC=175.180.104.218 DST=207.7.86.103 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=6609 PROTO=UDP SPT=39329 DPT=5446 LEN=28 Feb 11 08:44:52 host kernel: Firewall: *UDP_IN Blocked* IN=venet0 OUT= MAC= SRC=175.180.104.218 DST=207.7.86.103 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=6648 PROTO=UDP SPT=39329 DPT=5446 LEN=28 Feb 11 08:44:55 host kernel: Firewall: *UDP_IN Blocked* IN=venet0 OUT= MAC= SRC=175.180.104.218 DST=207.7.86.103 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=6832 PROTO=UDP SPT=39329 DPT=5446 LEN=28 Feb 11 08:45:01 host kernel: Firewall: *UDP_IN Blocked* IN=venet0 OUT= MAC= SRC=175.180.104.218 DST=207.7.86.103 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=7133 PROTO=UDP SPT=39329 DPT=5446 LEN=28 Feb 11 08:45:13 host kernel: Firewall: *UDP_IN Blocked* IN=venet0 OUT= MAC= SRC=175.180.104.218 DST=207.7.86.103 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=7639 PROTO=UDP SPT=39329 DPT=5446 LEN=28
Time: Mon Feb 11 08:45:15 2013 -0500
IP: 175.180.104.218 (TW/Taiwan/175-180-104-21
Hits: 11
Blocked: Temporary Block
Sample of block hits:
Feb 11 08:44:23 host kernel: Firewall: *UDP_IN Blocked* IN=venet0 OUT= MAC= SRC=175.180.104.218 DST=207.7.86.103 LEN=58 TOS=0x00 PREC=0x00 TTL=111 ID=5076 PROTO=UDP SPT=39329 DPT=5446 LEN=38 Feb 11 08:44:23 host kernel: Firewall: *UDP_IN Blocked* IN=venet0 OUT= MAC= SRC=175.180.104.218 DST=207.7.86.103 LEN=58 TOS=0x00 PREC=0x00 TTL=111 ID=5079 PROTO=UDP SPT=39329 DPT=5446 LEN=38 Feb 11 08:44:23 host kernel: Firewall: *UDP_IN Blocked* IN=venet0 OUT= MAC= SRC=175.180.104.218 DST=207.7.86.103 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=5080 PROTO=UDP SPT=39329 DPT=5446 LEN=28 Feb 11 08:44:26 host kernel: Firewall: *UDP_IN Blocked* IN=venet0 OUT= MAC= SRC=175.180.104.218 DST=207.7.86.103 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=5196 PROTO=UDP SPT=39329 DPT=5446 LEN=28 Feb 11 08:44:32 host kernel: Firewall: *UDP_IN Blocked* IN=venet0 OUT= MAC= SRC=175.180.104.218 DST=207.7.86.103 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=5529 PROTO=UDP SPT=39329 DPT=5446 LEN=28 Feb 11 08:44:44 host kernel: Firewall: *UDP_IN Blocked* IN=venet0 OUT= MAC= SRC=175.180.104.218 DST=207.7.86.103 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=6231 PROTO=UDP SPT=39329 DPT=5446 LEN=28 Feb 11 08:44:52 host kernel: Firewall: *UDP_IN Blocked* IN=venet0 OUT= MAC= SRC=175.180.104.218 DST=207.7.86.103 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=6609 PROTO=UDP SPT=39329 DPT=5446 LEN=28 Feb 11 08:44:52 host kernel: Firewall: *UDP_IN Blocked* IN=venet0 OUT= MAC= SRC=175.180.104.218 DST=207.7.86.103 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=6648 PROTO=UDP SPT=39329 DPT=5446 LEN=28 Feb 11 08:44:55 host kernel: Firewall: *UDP_IN Blocked* IN=venet0 OUT= MAC= SRC=175.180.104.218 DST=207.7.86.103 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=6832 PROTO=UDP SPT=39329 DPT=5446 LEN=28 Feb 11 08:45:01 host kernel: Firewall: *UDP_IN Blocked* IN=venet0 OUT= MAC= SRC=175.180.104.218 DST=207.7.86.103 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=7133 PROTO=UDP SPT=39329 DPT=5446 LEN=28 Feb 11 08:45:13 host kernel: Firewall: *UDP_IN Blocked* IN=venet0 OUT= MAC= SRC=175.180.104.218 DST=207.7.86.103 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=7639 PROTO=UDP SPT=39329 DPT=5446 LEN=28