Hey there,
I am running SuSe 9.1 and notice messages every few seconds in /var/log/messages like:
Jan 21 11:16:07 impi kernel: SFW2-INext-DROP-DEFLT IN=eth1 OUT= MAC=00:02:44:4f:3a:78:00:0e:2e:4f:2d:da:08:00 SRC=69.166.50.231 DST=192.168.2.103 LEN=90 TOS=0x00 PREC=0x00 TTL=110 ID=39140 PROTO=UDP SPT=6881 DPT=33329 LEN=70
Jan 21 11:16:08 impi kernel: SFW2-INext-ACC-TCP IN=eth1 OUT= MAC=00:02:44:4f:3a:78:00:0e:2e:4f:2d:da:08:00 SRC=207.172.210.35 DST=192.168.2.103 LEN=60 TOS=0x00 PREC=0x00 TTL=51 ID=19349 DF PROTO=TCP SPT=40399 DPT=33329 WINDOW=5840 RES=0x00 SYN URGP=0 OPT (0204059C0402080A04046C5B0000000001030302)
Jan 21 11:16:10 impi kernel: SFW2-INext-DROP-DEFLT IN=eth1 OUT= MAC=00:02:44:4f:3a:78:00:0e:2e:4f:2d:da:08:00 SRC=62.1.246.89 DST=192.168.2.103 LEN=90 TOS=0x00 PREC=0x00 TTL=111 ID=64976 PROTO=UDP SPT=52323 DPT=33329 LEN=70
Jan 21 11:16:11 impi kernel: SFW2-INext-DROP-DEFLT IN=eth1 OUT= MAC=00:02:44:4f:3a:78:00:0e:2e:4f:2d:da:08:00 SRC=80.171.49.45 DST=192.168.2.103 LEN=64 TOS=0x00 PREC=0x00 TTL=114 ID=35824 PROTO=UDP SPT=6881 DPT=33329 LEN=44
Jan 21 11:16:12 impi kernel: SFW2-INext-DROP-DEFLT IN=eth1 OUT= MAC=00:02:44:4f:3a:78:00:0e:2e:4f:2d:da:08:00 SRC=213.60.237.135 DST=192.168.2.103 LEN=69 TOS=0x00 PREC=0x00 TTL=112 ID=21735 PROTO=UDP SPT=6891 DPT=33329 LEN=49
Jan 21 11:16:22 impi kernel: SFW2-INext-DROP-DEFLT IN=eth1 OUT= MAC=00:02:44:4f:3a:78:00:0e:2e:4f:2d:da:08:00 SRC=83.135.17.146 DST=192.168.2.103 LEN=90 TOS=0x00 PREC=0x00 TTL=117 ID=20107 PROTO=UDP SPT=7001 DPT=33329 LEN=70
Jan 21 11:16:22 impi kernel: SFW2-INext-DROP-DEFLT IN=eth1 OUT= MAC=00:02:44:4f:3a:78:00:0e:2e:4f:2d:da:08:00 SRC=85.164.48.193 DST=192.168.2.103 LEN=90 TOS=0x00 PREC=0x00 TTL=50 ID=30430 DF PROTO=UDP SPT=6919 DPT=33329 LEN=70
Jan 21 11:16:22 impi kernel: SFW2-INext-DROP-DEFLT IN=eth1 OUT= MAC=00:02:44:4f:3a:78:00:0e:2e:4f:2d:da:08:00 SRC=70.178.221.71 DST=192.168.2.103 LEN=70 TOS=0x00 PREC=0x00 TTL=112 ID=21118 PROTO=UDP SPT=6881 DPT=33329 LEN=50
Jan 21 11:16:26 impi kernel: SFW2-INext-DROP-DEFLT IN=eth1 OUT= MAC=00:02:44:4f:3a:78:00:0e:2e:4f:2d:da:08:00 SRC=69.117.42.163 DST=192.168.2.103 LEN=90 TOS=0x00 PREC=0x00 TTL=115 ID=58025 PROTO=UDP SPT=51931 DPT=33329 LEN=70
Jan 21 11:16:27 impi kernel: SFW2-INext-DROP-DEFLT IN=eth1 OUT= MAC=00:02:44:4f:3a:78:00:0e:2e:4f:2d:da:08:00 SRC=220.233.7.197 DST=192.168.2.103 LEN=92 TOS=0x00 PREC=0x00 TTL=108 ID=14860 PROTO=UDP SPT=6881 DPT=33329 LEN=72
Jan 21 11:16:27 impi kernel: SFW2-INext-DROP-DEFLT IN=eth1 OUT= MAC=00:02:44:4f:3a:78:00:0e:2e:4f:2d:da:08:00 SRC=213.10.28.145 DST=192.168.2.103 LEN=90 TOS=0x00 PREC=0x00 TTL=118 ID=4424 PROTO=UDP SPT=6881 DPT=33329 LEN=70
Which seem to be messages from SuSe's firewall. I'm not sure exactly what they mean and if I should be concerned about them. It's strange that they seem to be coming from such a range of different IP addresses. I have stopped all running programs which connect to the internet and these messages continue. I have read through a few threads where people have had similar problems (such as
http://www.linuxquestions.org/questi...d.php?t=267395
) but nobody seems to be able to give an authoritative explanation of what this means. I'm also a bit worried that one of those messages is "SFW2-INext-ACC-TCP" as I don't expect to be accepting any incoming traffic from anyone.
Any ideas?