[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Problema impostazioni firewall UFW e multicast



Ciao,
Ho /var/log/messages pieni di questi messaggi di UFW che blocca comunicazioni multicast che credevo di aver consentito:

Jun  8 16:15:12 dc01 kernel: [77637.657358] [UFW BLOCK] IN=eth0 OUT= MAC=01:00:5e:40:00:00:00:21:5a:74:86:c1:08:00 SRC=192.168.0.18 DST=239.192.0.0 LEN=32 TOS=0x00 PREC=0xC0 TTL=1 ID=0 DF PROTO=2
Jun  8 16:15:14 dc01 kernel: [77640.115578] [UFW BLOCK] IN=eth0 OUT= MAC=01:00:5e:00:00:fb:00:21:5a:74:86:c1:08:00 SRC=192.168.0.18 DST=224.0.0.251 LEN=32 TOS=0x00 PREC=0xC0 TTL=1 ID=0 DF PROTO=2

Questo è l’output di ufw status numbered:

 sudo ufw status numbered
Status: active

     To                         Action      From
     --                         ------      ----
[ 1] 22                         ALLOW IN    Anywhere
[ 2] 123                        ALLOW IN    192.168.0.0/22
[ 3] 80                         ALLOW IN    192.168.0.0/22
[ 4] 443                        ALLOW IN    192.168.0.0/22
[ 5] 53                         ALLOW IN    192.168.0.0/22
[ 6] 5298                       ALLOW IN    192.168.0.0/22
[ 7] 5353                       ALLOW IN    192.168.0.0/22
[ 8] 515                        ALLOW IN    192.168.0.0/22
[ 9] 631                        ALLOW IN    192.168.0.0/22
[10] 9100                       ALLOW IN    192.168.0.0/22
[11] 445                        ALLOW IN    192.168.0.0/22
[12] 137                        ALLOW IN    192.168.0.0/22
[13] 138                        ALLOW IN    192.168.0.0/22
[14] 139                        ALLOW IN    192.168.0.0/22
[15] 389                        ALLOW IN    192.168.0.0/22
[16] 3142                       ALLOW IN    192.168.0.0/22
[17] 67/udp                     ALLOW IN    68/udp
[18] 3128                       ALLOW IN    192.168.0.0/22
[19] 11000                      ALLOW IN    Anywhere
[20] 224.0.0.0/4/udp            ALLOW IN    Anywhere
[21] 224.0.0.0/4/udp            ALLOW OUT   Anywhere (out)
[22] 11007                      ALLOW IN    Anywhere
[23] 12000                      ALLOW IN    Anywhere
[24] 67/udp                     ALLOW IN    68/udp
[25] 11000                      ALLOW IN    Anywhere (v6)
[26] 11007                      ALLOW IN    Anywhere (v6)
[27] 12000                      ALLOW IN    Anywhere (v6)


Credevo che le regole [20] e [21] fossero sufficienti a consentire le comunicazioni multicast, ma evidentemente ho sbagliato qualcosa. 

Che ne pensate? Dove potrebbe essere l’errore?

grazie a tutti in anticipo,
gerlos


--
"Fairy tales are more than true, not because they tell us that dragons exist, 
but because they tell us that dragons can be beaten."
					G. K. Chesterton
       <http://gerlos.altervista.org>
gerlos +- - - > gnu/linux registred user #311588


Reply to: