Diff Check Warning: Firewall rules removed/added?

Diff Check Warning: Firewall rules removed/added?

Postby Trikki » Sep 2nd, '16, 19:07

I have set up Mageia 5 (32-bit, KDE & LXDE) for my friends old computer. I am kind of unofficially the "tech support" guy so while a was visiting her today I looked through some logs and noticed something I haven't seen before. In the /var/log/security.log was repeatedly these two diff check warnings:

Code: Select all
diff: Security Warning: change in firewall rules found:
Removed firewall rules : -A Ifw -m set --match-set ifw_wl src -j RETURN
Removed firewall rules : -A Ifw -m set --match-set ifw_bl src -j DROP


and

Code: Select all
diff: Security Warning: change in firewall rules found:
Added firewall rules : -A Ifw -m set --match-set ifw_wl src -j RETURN
Added firewall rules : -A Ifw -m set --match-set ifw_bl src -j DROP


I do understand what it says that every once in a while those two firewall rules are added/removed. Also doing a bit of Google research have found out that apparently both of those are quite normal firewall rules as such. What I am not able to get a clear understanding is what do those rules actually do and why and how they are being removed/added repeatedly? And just to be clear: my friend said she has not done any changes (has not even ever logged in as root) and I have not done any changes to the system after installing it some months ago.
Trikki
 
Posts: 28
Joined: Feb 7th, '12, 19:13

Re: Diff Check Warning: Firewall rules removed/added?

Postby msjs08 » May 30th, '17, 03:45

I've seen this in the past and see something similar today.
Code: Select all
Security Warning: change in firewall rules found :
- Removed firewall rules : -N Ifw
- Removed firewall rules : -A INPUT -j Ifw
- Removed firewall rules : -A Ifw -m set --match-set ifw_wl src -j RETURN
- Removed firewall rules : -A Ifw -m set --match-set ifw_bl src -j DROP
- Removed firewall rules : -A Ifw -m conntrack --ctstate INVALID,NEW -m psd--psd-weight-threshold 10 --psd-delay-threshold 10000 --psd-lo-ports-weight 2 --psd-hi-ports-weight 1  -j IFWLOG--log-prefix "SCAN"


Did you ever figure out why?
Or does someone else know why rules get removed and then readded a few days later?
msjs08
 
Posts: 12
Joined: Jul 30th, '13, 09:32

Re: Diff Check Warning: Firewall rules removed/added?POS-SOL

Postby msjs08 » Jul 10th, '17, 02:33

"Security Warning: change in firewall rules found :" I think I have solved this puzzle!
I've had 14 such messages in the last 18mths.
6 of them were rules removed and 6 were the rules added back again.

It was starting to really bother me that maybe my security had been compromised. I using Mageia 5 and had been planning to upgrade.

This week I had another "2 rules removed" message but I remembered we had had a power cut the day before. So yesterday I restarted the desktop computer and sure enough, today I get a message to say "2 rules added".

Can anyone else check their logs for improper shutdown, startup following improper shutdown with the 2 rules removed and finally a restart with the 2 rules added back the next day or later?
I'm not sure if it happens every time there is an improper shutdown. My uptimes are sometimes as high as 60 days so the 2 messages can be quite a distance apart.

Regards
Max
msjs08
 
Posts: 12
Joined: Jul 30th, '13, 09:32


Return to Networking

Who is online

Users browsing this forum: No registered users and 1 guest