Score:0

Allowed IP's are logged as blocked by UFW

de flag

The rule in UFW for SR.CSR.CS.RC IP is:

ufw allow from SR.CSR.CS.RC

As described in the rule, SR.CSR.CS.RC can access this server over any enabled port.

But, when UFW is up and running, some lines are appears in UFW log file about request from SR.CSR.CS.RC IP has been blocked.

[UFW BLOCK] IN=ens3 OUT= MAC=11:00:11:00:11:ff:00:11:11:bb:ee:00:00:00 SRC=SR.CSR.CS.RC DST=D.ST.DST.DST LEN=52 TOS=0x00 PREC=0x00 TTL=63 ID=xyxyxy DF PROTO=TCP SPT=SPTSP DPT=SPTDP WINDOW=501 RES=0x00 ACK FIN URGP=0

Why am I seeing those logs while SR.CSR.CS.RC IP has be full access? Is it possible to UFW considers requests from SR.CSR.CS.RC IP are DOS attacks?

Note: SR.CSR.CS.RC is IP in disguise

Is this entry related with this: UFW logs blocked request on open port, what am I missing?

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.