ipfw is making contact with 198.61.170.85 port 4021

Ernie Luzar luzar722 at gmail.com
Fri Jul 24 01:47:49 UTC 2020


RW via freebsd-questions wrote:
> On Thu, 23 Jul 2020 21:11:39 -0400
> Ernie Luzar wrote:
> 
>> A firewall should not be making its own contact with any public ip 
>> address. This is a security hole.
>>
>> I have not played with ipfw since before it was rewritten to become 
>> ipfw2 so I do not know when this internal "call home"  function was 
>> added. pf and ipf are not doing this. I block it to be secure.
>>
>> Can any one provide any info about this?
> 
> It might help if you explain what you have actually seen.

I see log entries in the hosts /var/log/security file for outbound 
packets going to the ip address and port number comming from 10.0.10.1 
which is the private ip address of the host. sendmail is turned off and 
nothing else is running on the host


More information about the freebsd-questions mailing list