Witam,
W logach kernel mam duzo dziwnych wpisów dot layer7, plik kernel ma bardzo duza wielkosc, czasami nawet nie da sie go otworzyc, caly czas pojawiaja sie te wpisy, co to moze byc? oto wycinek:
Oct 17 08:40:21 rudnet kernel: l7-filter gave up after 846 bytes (11 packets):
Oct 17 08:40:21 rudnet kernel: .........200.130.180.213.in-addr.arpa .. .....f1virt.onet.pl........dns astercity.net........d
Oct 17 08:40:21 rudnet kernel: In hex: 02 d7 81 80 01 01 03 03 03 32 30 30 03 31 33 30 03 31 38 30 03 32 31 33 07 69 6e 2d 61
Oct 17 08:40:37 rudnet kernel: c 01 c0 0c 0c 01 15 30 10 0layer7: regexec positive: bittorrent!
Oct 17 08:40:37 rudnet kernel: layer7: regexec positive: bittorrent!
Oct 17 08:41:28 rudnet last message repeated 4 times
Oct 17 08:41:30 rudnet kernel: layer7: regexec positive: bittorrent!
Oct 17 08:41:34 rudnet kernel: layer7: regexec positive: edonkey!
Oct 17 08:41:46 rudnet kernel: layer7: regexec positive: bittorrent!
Oct 17 08:41:50 rudnet kernel: layer7: regexec positive: edonkey!
Oct 17 08:42:06 rudnet last message repeated 2 times
Oct 17 08:42:08 rudnet kernel: layer7: regexec positive: bittorrent!
Oct 17 08:42:16 rudnet kernel:
Oct 17 08:42:16 rudnet kernel: l7-filter gave up after 274 bytes (11 packets):
Oct 17 08:42:16 rudnet kernel: .c6.zx2..;=....e.u.....{.e"9..t..k0.t.xaao\k.o...d$....2. ;\....+..du6z.i.q7...aao\k.o..$.....
Oct 17 08:42:16 rudnet kernel: In hex: 0b 91 63 36 16 7a 78 32 a5 f6 3b 3d 8f 9d d1 90 65 d1 75 cf ac 03 de b5 7b 8c 65 22 39
Oct 17 08:42:19 rudnet kernel: layer7: regexec positive: bittorrent!
Oct 17 08:42:23 rudnet kernel:
Oct 17 08:42:23 rudnet kernel: l7-filter gave up after 1560 bytes (11 packets):
Oct 17 08:42:23 rudnet kernel: .... .tv. ...ttv..uvqsw..u.t...svuv....q..q.qv.t.u.. qv.s.u.svvs. . .qtq uv ....u..u.. .q.....
Oct 17 08:42:23 rudnet kernel: 09 07 74 76 03 09 0b 01 07 02 74 74 76 07 02 75 76 71 73 77 04 07 75 08 74 01 07 01 73 76 75 76
Oct 17 08:42:24 rudnet kernel: 23 flayer7: regexec positive: bittorrent!
Oct 17 08:42:27 rudnet kernel: layer7: regexec positive: bittorrent!
Oct 17 08:42:49 rudnet last message repeated 2 times
Oct 17 08:42:49 rudnet kernel: layer7: regexec positive: edonkey!
Oct 17 08:42:50 rudnet last message repeated 2 times
Oct 17 08:42:58 rudnet kernel: layer7: regexec positive: bittorrent!
Oct 17 08:42:59 rudnet last message repeated 2 times
Oct 17 08:43:00 rudnet kernel: layer7: regexec positive: ares!
Oct 17 08:43:04 rudnet kernel: layer7: regexec positive: bittorrent!
Oct 17 08:43:04 rudnet kernel: layer7: regexec positive: bittorrent!