1

These are the logs down below.

[DESTROY] udp      17 src=0.0.0.0 dst=0.0.0.0 sport=0 dport=0 packets=3 bytes=216 [UNREPLIED] src=0.0.0.0 dst=0.0.0.0 sport=0 dport=0 packets=0 bytes=0
    [NEW] udp      17 30 src=0.0.0.0 dst=0.0.0.0 sport=0 dport=0 [UNREPLIED] src=0.0.0.0 dst=0.0.0.0 sport=0 dport=0
    [NEW] udp      17 30 src=0.0.0.0 dst=0.0.0.0 sport=0 dport=0 [UNREPLIED] src=0.0.0.0 dst=0.0.0.0 sport=0 dport=0
[DESTROY] udp      17 src=0.0.0.0 dst=0.0.0.0 sport=0 dport=0 packets=1 bytes=71 [UNREPLIED] src=0.0.0.0 dst=0.0.0.0 sport=0 dport=0 packets=0 bytes=0
[DESTROY] udp      17 src=0.0.0.0 dst=0.0.0.0 sport=0 dport=0 packets=1 bytes=229 [UNREPLIED] src=0.0.0.0 dst=0.0.0.0 sport=0 dport=0 packets=0 bytes=0
[DESTROY] udp      17 src=0.0.0.0 dst=0.0.0.0 sport=0 dport=0 packets=1 bytes=32 [UNREPLIED] src=0.0.0.0 dst=0.0.0.0 sport=0 dport=0 packets=0 bytes=0
[DESTROY] udp      17 src=0.0.0.0 dst=0.0.0.0 sport=0 dport=0 packets=1 bytes=32 [UNREPLIED] src=0.0.0.0 dst=0.0.0.0 sport=0 dport=0 packets=0 bytes=0
^Cconntrack v0.9.13 (conntrack-tools): 7 flow events have been shown.

kernel Version: 2.6.34

Library Used/Version: libnetfilter_conntrack.so.3.0.0

Dynamic Modules inserted: lsmod | grep conn

nf_conntrack_netlink    14931  0 
nfnetlink               3836  3 nf_conntrack_netlink,nfnetlink_queue
nf_conntrack_sip       19872  1 nf_nat_sip
nf_conntrack_h323      49589  1 nf_nat_h323
nf_conntrack_pptp       4910  1 nf_nat_pptp
nf_conntrack_proto_gre     3910  1 nf_conntrack_pptp
nf_conntrack_ftp        6023  1 nf_nat_ftp
nf_conntrack_amanda     2673  1 nf_nat_amanda
nf_conntrack_irc        4197  1 nf_nat_irc
nf_conntrack_tftp       3825  1 nf_nat_tftp

Builtin modules: cat /lib/modules/linux-2.6.34/modules.builtin | grep conn

kernel/drivers/connector/cn.ko
kernel/net/ipv4/netfilter/nf_conntrack_ipv4.ko
kernel/net/netfilter/nf_conntrack.ko

although I can see the SRC and DST ips in the /proc/net/nf_conntrack and /proc/net/ip_conntrack

jatinBatra
  • 41
  • 4

0 Answers0