Results 1 to 7 of 7

Thread: Strange PREROUTING rules

  1. #1

    Strange PREROUTING rules

    My router shows the following rule in /tmp/nat_rules:

    Code:
    /tmp/nat_rules:-A PREROUTING -p udp -m udp -d <my public ip address> --dport 31104 -j DNAT --to-destination 192.168.1.201:16664
    When I access the NAT section from the webpage, this rule does not show up. Only my port forwarding rules for my internal webserver (ports 80 and 443) and the SSH port (22) are shown.

    Two questions:
    1) How did it get there (I did not enter it myself)?
    2) How to remove it?

    Thanks,
    joozju

  2. #2
    Join Date
    Sep 2004
    Location
    Austria
    Posts
    125
    Maybe upnp is the culprit. (If you have it enabled )

  3. #3
    Join Date
    Jun 2005
    Location
    Far out in the wild forests of Sweden
    Posts
    15

    Question Strange PREROUTING rules


    Yes, I also saw something very similar. Got very worried, tried in vain to get it away via the web interface. Finally rebooted the router - and it was gone.
    Is this a sign that someone has compromised the network and set it up like this, or does it have some natural cause, like some legal traffic originating from inside making the kernel set this up for reply traffic? Anybody knows?

  4. #4
    Join Date
    Dec 2003
    Location
    Russian Federation
    Posts
    8,356
    As wztm said - DISABLE UPnP.

  5. #5

    I have...

    As suggested, I looked at this configuration parameter but my setting at "Enable UPnP" is set to "No". It could be that the Plug-and-Play device has to "unregister"? Because the PREROUTING rule is still there.

  6. #6
    Join Date
    Dec 2003
    Location
    Russian Federation
    Posts
    8,356

  7. #7
    There is also this thread on howto remove entries..
    http://wl500g.info/showthread.php?t=1933

Similar Threads

  1. WL-300g Strange Wlan problem
    By sergis in forum WL-300g Custom Development
    Replies: 1
    Last Post: 11-05-2005, 06:56
  2. Strange compiler errors ... help
    By ezhikov in forum WL-HDD Custom Development
    Replies: 2
    Last Post: 15-02-2005, 10:42
  3. Strange Powerdrops
    By FvW in forum WL-500g Q&A
    Replies: 0
    Last Post: 26-07-2004, 21:01
  4. Strange problem with customized firmware
    By perms in forum WL-500g Custom Development
    Replies: 2
    Last Post: 16-03-2004, 11:02

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •