Welcome, Guest. Please login or register.
Did you miss your activation email?
Saturday 20 April 2024, 08:02:56 pm

Login with username, password and session length

CLICK HERE for the The official Endian Roadmap and Issue tracker
14247 Posts in 4376 Topics by 6491 Members
Latest Member: roy
Search:     Advanced search
+  EFW Support
|-+  Support
| |-+  General Support
| | |-+  [strange messages] tail -f /var/log/messages
0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: [strange messages] tail -f /var/log/messages  (Read 8183 times)
Linjan
Jr. Member
*
Offline Offline

Posts: 2


« on: Wednesday 17 June 2009, 11:08:45 pm »

I am using EFW on the machine with real ip.
Last time i've got these messages in log:
Code:
Jun 17 17:03:08 efw-1245173387 kernel: device eth0 entered promiscuous mode
Jun 17 17:03:08 efw-1245173387 kernel: audit(1245243788.888:22): dev=eth0 prom=256 old_prom=0 auid=4294967295
Jun 17 17:03:08 efw-1245173387 kernel: device eth0 left promiscuous mode
Jun 17 17:03:08 efw-1245173387 kernel: audit(1245243788.900:23): dev=eth0 prom=0 old_prom=256 auid=4294967295
Jun 17 17:03:08 efw-1245173387 snort[28627]: Initializing daemon mode
Jun 17 17:03:08 efw-1245173387 kernel: device eth0 entered promiscuous mode
Jun 17 17:03:08 efw-1245173387 kernel: audit(1245243788.912:24): dev=eth0 prom=256 old_prom=0 auid=4294967295
What it means?
Logged
gyp_the_cat
Full Member
***
Offline Offline

Posts: 81



WWW
« Reply #1 on: Thursday 25 June 2009, 11:52:03 pm »

Hi Linjan,

Are you running Snort (IDS) on your EFW?

This could be something to do with the intrusion detecting sniffing the packets on it's real IP interface.

Gyp
Logged
Pages: [1] Go Up Print 
« previous next »
Jump to:  

Page created in 0.031 seconds with 18 queries.
Powered by SMF 1.1 RC2 | SMF © 2001-2005, Lewis Media Design by 7dana.com