[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Debian 12 - IPv4 blocked without fail2ban & co



On 07/09/2023 17:32, Andy Smith wrote:
On Thu, Sep 07, 2023 at 12:20:18PM +0200, Romain wrote:
With -n (sometimes it stops at hop 7, sometimes 9):
└─# mtr -nr 54.38.38.159 -4
Start: 2023-09-07T08:17:12+0000
HOST: rpi4                        Loss%   Snt   Last   Avg  Best  Wrst StDev
         ^^^^
   9.|-- 192.168.0.2               90.0%    10  3461. 3461. 3461. 3461.   0.0
To me this suggests that the ICMP Time Exceeded packet is arriving
with source address 192.168.0.2, which I think means it is being
sent to you by your own ISP.

I guess, these packets are generated by localhost = rpi4.home = 192.168.0.2. At first I did not noticed excessively large time in the last line.

Concerning question related to .home, perhaps it is just /etc/hosts with
192.168.0.1 livebox.home
192.168.0.2 rpi4.home

I do not suspect some peculiarities in local configuration anymore. tcpdump on the server may shed some light if packets from localhost arrive to it.


Reply to: