Page 1 of 1

UDP Out Blocked?

Posted: 29 Nov 2015, 23:55
by nootkan
Was wondering if someone could shed some light on this log message and tell me whether it is a normal spam assassin call that is being blocked by csf and if that is normal or is something misconfigured in csf? The dst port is 24441 which Pyzor uses to communicate with the server. I am seeing these every hour and it is quite annoying to say the least. Is there something amiss or can I somehow stop these notifications for this log line only?

I also see this in my logview file: From my ip address - 110 packets to udp(24441); usually there is over 175 packets to udp (24441) per day.
Nov 29 13:00:12 my domain kernel: [8055252.877644] Firewall: *UDP_OUT Blocked* IN= OUT=eth0 SRC=myipaddress DST=5.9.124.53 LEN=192 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=UDP SPT=38706 DPT=24441 LEN=172 UID=47 GID=12
Nov 29 13:09:27 my domain kernel: [8055808.398741] Firewall: *UDP_OUT Blocked* IN= OUT=eth0 SRC=my ip address DST=5.9.124.53 LEN=191 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=UDP SPT=52389 DPT=24441 LEN=171 UID=47 GID=12
Nov 29 13:12:33 my domain kernel: [8055993.926752] Firewall: *UDP_OUT Blocked* IN= OUT=eth0 SRC=my ip address DST=5.9.124.53 LEN=192 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=UDP SPT=52206 DPT=24441 LEN=172 UID=47 GID=12
Nov 29 13:29:56 my domain kernel: [8057037.245094] Firewall: *UDP_OUT Blocked* IN= OUT=eth0 SRC=my ip address DST=5.9.124.53 LEN=192 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=UDP SPT=55354 DPT=24441 LEN=172 UID=47 GID=12
Nov 29 13:37:23 my domain kernel: [8057484.195245] Firewall: *UDP_OUT Blocked* IN= OUT=eth0 SRC=my ip address DST=5.9.124.53 LEN=192 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=UDP SPT=56330 DPT=24441 LEN=172 UID=47 GID=12

Re: UDP Out Blocked?

Posted: 30 Nov 2015, 08:19
by ForumAdmin
cPanel recently added Pyzor to the exim configuration. It would seem sensible to simply add the port to UDP_OUT which the latest new csf installs on cPanel already do.

Re: UDP Out Blocked?

Posted: 30 Nov 2015, 20:51
by nootkan
Okay thanks. I was just concerned that because csf disables spam assassin and use it's own combination that there was something amiss. I will add the port to UDP_OUT. Thanks for the support.