Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 10 Nov 1999 10:50:28 +1100
From:      Peter Jeremy <jeremyp@gsmx07.alcatel.com.au>
To:        Larry Sica <larry@interactivate.com>
Cc:        freebsd-questions@FreeBSD.ORG
Subject:   Re: Port 137 hitting my server
Message-ID:  <99Nov10.104437est.40326@border.alcanet.com.au>
In-Reply-To: <Pine.SOL.4.10.9911091512360.25266-100000@icg>
References:  <86emdz68a0.fsf@localhost.hell.gr> <Pine.SOL.4.10.9911091512360.25266-100000@icg>

next in thread | previous in thread | raw e-mail | index | archive | help
On 1999-Nov-10 10:13:17 +1100, Larry Sica wrote:
>actually the only thing i'd want to do is get rid of the annoying log
>messages.  How could i tell syslog not to log that particular things (this
>is veering offt opic now i think)

This is something for -questions.  You are getting messages like:

Connection attempt to UDP 192.168.123.123:137 from 192.168.234.3:137

because you have the sysctl net.inet.udp.log_in_vain (and probably
net.inet.tcp.log_in_vain) set to 1.  These are controlled by the
rc.conf parameter log_in_vain, (which defaults to "NO" ie off).

You can remove all the `Connection attempt' messages by removing the
line 'log_in_vain="YES"' from your /etc/rc.conf.

If you just wait to stop messages about port 137 (or other specific
ports), your only option is to have a daemon listening on this port
and silently dropping all traffic for it.  (I don't believe a suitable
daemon comes with FreeBSD, but would be trivial to write).

Peter


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?99Nov10.104437est.40326>