weird outbound traffic - Page 2
Page 2 of 2 FirstFirst 12
Results 11 to 12 of 12

Thread: weird outbound traffic

  1. #11
    Jaded Network Admin nebulus200's Avatar
    Join Date
    Jun 2002
    Posts
    1,356
    By chance have dual NIC cards (or more)? 169.254 is the default IP addr used by many versions of Microsoft windows for an unconfigured NIC...

    Basically it looks to me like your system is getting the DNS request in on one interface and then for some reason a response is being picked up on the unconfigured NIC and being properly dropped by the firewall...I would check and make sure all non-configured interfaces are disabled, that you haven't enabled IPforwarding, and then have a look again...
    There is only one constant, one universal, it is the only real truth: causality. Action. Reaction. Cause and effect...There is no escape from it, we are forever slaves to it. Our only hope, our only peace is to understand it, to understand the 'why'. 'Why' is what separates us from them, you from me. 'Why' is the only real social power, without it you are powerless.

    (Merovingian - Matrix Reloaded)

  2. #12
    Just Another Geek
    Join Date
    Jul 2002
    Location
    Rotterdam, Netherlands
    Posts
    3,403
    We can look at the firewall logs but we'll never figure out what is happening.

    Kitaserupa2000: Please use a sniffer to analyse your traffic, cross-reference that with your firewall logs.
    Without knowing what's really "on the wire" you'll be guessing till the cows come home
    Oliver's Law:
    Experience is something you don't get until just after you need it.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

 Security News

     Patches

       Security Trends

         How-To

           Buying Guides