I have been seeing a lot of these entries in my logs lately. Could this be some sort of legitimate traffic triggering this ipchains rule? Or is it just plain spoofing attempt by someone? Thanks David kernel: Packet log: input DENY eth1 PROTO=17 127.0.0.1:2301 255.255.255.255:2301 L=240 S=0x00 I=674 F=0x0000 T=128 (#2) kernel: Packet log: input DENY eth1 PROTO=17 127.0.0.1:2301 255.255.255.255:2301 L=40 S=0x00 I=801 F=0x0000 T=128 (#2)