I see a lot of these in my firewall log:
Code: Select all
18:10:27 firewall,info dropINVALID forward: in:bridge-local out:G1-world, src-mac d8:bb:2c:b9:67:40, proto TCP (ACK,FIN), 192.168.0.106:65002->108.160.165.10:443, len 52
18:10:38 firewall,info dropINVALID forward: in:bridge-local out:G1-world, src-mac d8:bb:2c:b9:67:40, proto TCP (RST), 192.168.0.106:65009->23.21.152.241:443, len 40
18:10:38 firewall,info dropINVALID forward: in:bridge-local out:G1-world, src-mac d8:bb:2c:b9:67:40, proto TCP (RST), 192.168.0.106:65009->23.21.152.241:443, len 40
18:10:42 firewall,info dropINVALID forward: in:bridge-local out:G1-world, src-mac d8:bb:2c:b9:67:40, proto TCP (ACK,FIN), 192.168.0.106:65002->108.160.165.10:443, len 52
18:10:52 firewall,info dropINVALID forward: in:bridge-local out:G1-world, src-mac d8:bb:2c:b9:67:40, proto TCP (ACK,FIN), 192.168.0.106:64971->74.112.185.182:443, len 52
18:10:57 firewall,info dropINVALID forward: in:bridge-local out:G1-world, src-mac d8:bb:2c:b9:67:40, proto TCP (ACK,FIN), 192.168.0.106:65002->108.160.165.10:443, len 52
18:11:12 firewall,info dropINVALID forward: in:bridge-local out:G1-world, src-mac d8:bb:2c:b9:67:40, proto TCP (ACK,FIN), 192.168.0.106:65002->108.160.165.10:443, len 52
18:11:27 firewall,info dropINVALID forward: in:bridge-local out:G1-world, src-mac d8:bb:2c:b9:67:40, proto TCP (ACK,FIN), 192.168.0.106:65002->108.160.165.10:443, len 52
18:11:28 firewall,info dropINVALID forward: in:bridge-local out:G1-world, src-mac d8:bb:2c:b9:67:40, proto TCP (ACK,FIN), 192.168.0.106:64971->74.112.185.182:443, len 52
18:11:43 firewall,info dropINVALID forward: in:bridge-local out:G1-world, src-mac d8:bb:2c:b9:67:40, proto TCP (ACK,FIN), 192.168.0.106:65002->108.160.165.10:443, len 52
18:11:51 firewall,info dropINVALID forward: in:bridge-local out:G1-world, src-mac d8:bb:2c:b9:67:40, proto TCP (ACK,FIN), 192.168.0.106:65014->108.160.167.148:443, len 52
18:11:52 firewall,info dropINVALID forward: in:bridge-local out:G1-world, src-mac d8:bb:2c:b9:67:40, proto TCP (ACK,FIN), 192.168.0.106:65014->108.160.167.148:443, len 52
18:11:53 firewall,info dropINVALID forward: in:bridge-local out:G1-world, src-mac d8:bb:2c:b9:67:40, proto TCP (ACK,FIN), 192.168.0.106:65014->108.160.167.148:443, len 52
18:11:54 firewall,info dropINVALID forward: in:bridge-local out:G1-world, src-mac d8:bb:2c:b9:67:40, proto TCP (ACK,FIN), 192.168.0.106:65014->108.160.167.148:443, len 52
18:11:58 firewall,info dropINVALID forward: in:bridge-local out:G1-world, src-mac d8:bb:2c:b9:67:40, proto TCP (ACK,RST), 192.168.0.106:65002->108.160.165.10:443, len 40
18:11:58 firewall,info dropINVALID forward: in:bridge-local out:G1-world, src-mac d8:bb:2c:b9:67:40, proto TCP (ACK,FIN), 192.168.0.106:65014->108.160.167.148:443, len 52
18:12:03 firewall,info dropINVALID forward: in:bridge-local out:G1-world, src-mac d8:bb:2c:b9:67:40, proto TCP (ACK,FIN), 192.168.0.106:64971->74.112.185.182:443, len 52
18:12:04 firewall,info dropINVALID forward: in:bridge-local out:G1-world, src-mac d8:bb:2c:b9:67:40, proto TCP (ACK,FIN), 192.168.0.106:65014->108.160.167.148:443, len 52
18:12:12 firewall,info dropINVALID forward: in:bridge-local out:G1-world, src-mac d8:bb:2c:b9:67:40, proto TCP (ACK,FIN), 192.168.0.106:65014->108.160.167.148:443, len 52
grep dropINVALID ll.txt |cut -d">" -f2 | cut -d":" -f1 | sort | uniq -c | sort -nr | while read C A; do echo -n "$C "; host $A; done
70 148.167.160.108.in-addr.arpa domain name pointer d-6b.v.dropbox.com.
70 145.167.160.108.in-addr.arpa domain name pointer d-1.v.dropbox.com.
56 61.166.160.108.in-addr.arpa domain name pointer d-5b.sjc.dropbox.com.
56 189.165.160.108.in-addr.arpa domain name pointer d-6a.sjc.dropbox.com.
56 7.222.243.103.in-addr.arpa domain name pointer float.1440.bm-impbus.prod.sin1.adnexus.net.
42 61.222.243.103.in-addr.arpa domain name pointer float.1767.bm-impbus.prod.sin1.adnexus.net.
42 15.222.243.103.in-addr.arpa domain name pointer float.1207.bm-impbus.prod.sin1.adnexus.net.
36 189.166.160.108.in-addr.arpa domain name pointer d-5a.sjc.dropbox.com.
28 Host 182.185.112.74.in-addr.arpa. not found: 3(NXDOMAIN)
27 Host 85.184.112.74.in-addr.arpa. not found: 3(NXDOMAIN)
27 190.174.225.54.in-addr.arpa domain name pointer ec2-54-225-174-190.compute-1.amazonaws.com.
19 241.152.21.23.in-addr.arpa domain name pointer ec2-23-21-152-241.compute-1.amazonaws.com.
14 137.166.160.108.in-addr.arpa domain name pointer client-14b.v.dropbox.com.
14 10.165.160.108.in-addr.arpa domain name pointer client-11a.v.dropbox.com.
14 63.222.243.103.in-addr.arpa domain name pointer float.1178.bm-impbus.prod.sin1.adnexus.net.
14 41.222.243.103.in-addr.arpa domain name pointer float.1766.bm-impbus.prod.sin1.adnexus.net.
9 Host 100.68.125.74.in-addr.arpa. not found: 3(NXDOMAIN)
9 95.200.125.74.in-addr.arpa domain name pointer sa-in-f95.1e100.net.
9 87.200.7.103.in-addr.arpa domain name pointer cache.google.com.
9 123.200.7.103.in-addr.arpa domain name pointer cache.google.com.
9 121.200.7.103.in-addr.arpa domain name pointer cache.google.com.
8 165.191.251.54.in-addr.arpa domain name pointer ec2-54-251-191-165.ap-southeast-1.compute.amazonaws.com.
7 Host 49.18.239.54.in-addr.arpa. not found: 3(NXDOMAIN)
7 50.222.243.103.in-addr.arpa domain name pointer float.1177.bm-impbus.prod.sin1.adnexus.net.
4 65.42.234.77.in-addr.arpa domain name pointer r-065-042-234-077.ff.avast.com.
2 103.242.251.205.in-addr.arpa domain name pointer s3-console-us-standard.console.aws.amazon.com.
1 Host 58.215.21.72.in-addr.arpa. not found: 3(NXDOMAIN)
1 Host 233.195.21.72.in-addr.arpa. not found: 3(NXDOMAIN)
1 Host 87.194.21.72.in-addr.arpa. not found: 3(NXDOMAIN)
1 76.8.17.216.in-addr.arpa is an alias for 76.0/24.8.17.216.in-addr.arpa.
76.0/24.8.17.216.in-addr.arpa domain name pointer central.crashplan.com.
1 253.162.171.207.in-addr.arpa domain name pointer 162-253.amazon.com.
1 116.73.233.205.in-addr.arpa domain name pointer www.tunnelblick.org.
1 Host 181.101.238.191.in-addr.arpa. not found: 3(NXDOMAIN)
1 Host 12.216.60.185.in-addr.arpa. not found: 3(NXDOMAIN)
1 Host 228.100.32.176.in-addr.arpa. not found: 3(NXDOMAIN)
1 217.218.252.125.in-addr.arpa domain name pointer a125-252-218-217.deploy.akamaitechnologies.com.
1 9.166.160.108.in-addr.arpa domain name pointer client-17a.v.dropbox.com.
1 83.165.160.108.in-addr.arpa domain name pointer client-8a.v.dropbox.com.
1 212.165.160.108.in-addr.arpa domain name pointer client-9b.v.dropbox.com.