Home of the Squeezebox™ & Transporter® network music players.
Results 1 to 6 of 6
  1. #1
    Senior Member gharris999's Avatar
    Join Date
    Apr 2005
    Location
    Santa Fe, NM
    Posts
    3,299

    Strange network traffic

    I just noticed this in my ubuntu box's dmesg:
    Code:
    [ 3783.689658] [UFW BLOCK] IN=eth0 OUT= MAC=00:21:85:97:b6:c5:00:04:20:06:29:30:08:00 SRC=192.168.0.7 DST=192.168.0.222 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=8486 PROTO=TCP SPT=7435 DPT=3483 WINDOW=3000 RES=0x00 RST URGP=0
    [ 3803.692332] [UFW BLOCK] IN=eth0 OUT= MAC=00:21:85:97:b6:c5:00:04:20:06:29:30:08:00 SRC=192.168.0.7 DST=192.168.0.222 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=8514 PROTO=TCP SPT=7437 DPT=3483 WINDOW=3000 RES=0x00 RST URGP=0
    [ 3823.702774] [UFW BLOCK] IN=eth0 OUT= MAC=00:21:85:97:b6:c5:00:04:20:06:29:30:08:00 SRC=192.168.0.7 DST=192.168.0.222 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=8542 PROTO=TCP SPT=7439 DPT=3483 WINDOW=3000 RES=0x00 RST URGP=0
    [ 3843.712546] [UFW BLOCK] IN=eth0 OUT= MAC=00:21:85:97:b6:c5:00:04:20:06:29:30:08:00 SRC=192.168.0.7 DST=192.168.0.222 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=8570 PROTO=TCP SPT=7441 DPT=3483 WINDOW=3000 RES=0x00 RST URGP=0
    [ 3863.721763] [UFW BLOCK] IN=eth0 OUT= MAC=00:21:85:97:b6:c5:00:04:20:06:29:30:08:00 SRC=192.168.0.7 DST=192.168.0.222 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=8598 PROTO=TCP SPT=7443 DPT=3483 WINDOW=3000 RES=0x00 RST URGP=0
    [ 3883.730390] [UFW BLOCK] IN=eth0 OUT= MAC=00:21:85:97:b6:c5:00:04:20:06:29:30:08:00 SRC=192.168.0.7 DST=192.168.0.222 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=8626 PROTO=TCP SPT=7445 DPT=3483 WINDOW=3000 RES=0x00 RST URGP=0
    [ 3903.738515] [UFW BLOCK] IN=eth0 OUT= MAC=00:21:85:97:b6:c5:00:04:20:06:29:30:08:00 SRC=192.168.0.7 DST=192.168.0.222 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=8654 PROTO=TCP SPT=7447 DPT=3483 WINDOW=3000 RES=0x00 RST URGP=0
    [ 3923.746171] [UFW BLOCK] IN=eth0 OUT= MAC=00:21:85:97:b6:c5:00:04:20:06:29:30:08:00 SRC=192.168.0.7 DST=192.168.0.222 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=8682 PROTO=TCP SPT=7449 DPT=3483 WINDOW=3000 RES=0x00 RST URGP=0
    [ 3943.753794] [UFW BLOCK] IN=eth0 OUT= MAC=00:21:85:97:b6:c5:00:04:20:06:29:30:08:00 SRC=192.168.0.7 DST=192.168.0.222 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=8710 PROTO=TCP SPT=7451 DPT=3483 WINDOW=3000 RES=0x00 RST URGP=0
    [ 3963.760144] [UFW BLOCK] IN=eth0 OUT= MAC=00:21:85:97:b6:c5:00:04:20:06:29:30:08:00 SRC=192.168.0.7 DST=192.168.0.222 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=8738 PROTO=TCP SPT=7453 DPT=3483 WINDOW=3000 RES=0x00 RST URGP=0
    [ 3983.766560] [UFW BLOCK] IN=eth0 OUT= MAC=00:21:85:97:b6:c5:00:04:20:06:29:30:08:00 SRC=192.168.0.7 DST=192.168.0.222 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=8766 PROTO=TCP SPT=7455 DPT=3483 WINDOW=3000 RES=0x00 RST URGP=0
    [ 4003.772615] [UFW BLOCK] IN=eth0 OUT= MAC=00:21:85:97:b6:c5:00:04:20:06:29:30:08:00 SRC=192.168.0.7 DST=192.168.0.222 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=8794 PROTO=TCP SPT=7457 DPT=3483 WINDOW=3000 RES=0x00 RST URGP=0
    [ 4023.778361] [UFW BLOCK] IN=eth0 OUT= MAC=00:21:85:97:b6:c5:00:04:20:06:29:30:08:00 SRC=192.168.0.7 DST=192.168.0.222 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=8822 PROTO=TCP SPT=7459 DPT=3483 WINDOW=3000 RES=0x00 RST URGP=0
    [ 4043.783789] [UFW BLOCK] IN=eth0 OUT= MAC=00:21:85:97:b6:c5:00:04:20:06:29:30:08:00 SRC=192.168.0.7 DST=192.168.0.222 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=8850 PROTO=TCP SPT=7461 DPT=3483 WINDOW=3000 RES=0x00 RST URGP=0
    [ 4063.789521] [UFW BLOCK] IN=eth0 OUT= MAC=00:21:85:97:b6:c5:00:04:20:06:29:30:08:00 SRC=192.168.0.7 DST=192.168.0.222 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=8878 PROTO=TCP SPT=7463 DPT=3483 WINDOW=3000 RES=0x00 RST URGP=0
    [ 4083.797773] [UFW BLOCK] IN=eth0 OUT= MAC=00:21:85:97:b6:c5:00:04:20:06:29:30:08:00 SRC=192.168.0.7 DST=192.168.0.222 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=8906 PROTO=TCP SPT=7465 DPT=3483 WINDOW=3000 RES=0x00 RST URGP=0
    So, those are firewall block messages and it appears to be blocks related to TCP traffic directed at port 3483 (slim discovery) coming from my SB3 (a.k.a. SBClassic).

    I thought everything on 3483 was UDP only. Should we be opening our firewalls on 3483 to TCP too?

  2. #2
    Senior Member bluegaspode's Avatar
    Join Date
    Jul 2009
    Location
    Berlin, Germany
    Posts
    3,051
    3483 UDP is the discovery protocol.
    3483 TCP is SlimProto, the protocol which has all the low level playback and synchronization commands.

    Without 3483 TCP playback won't work.
    Did you know: SqueezePlayer will stream all your music to your Android device. Take your music everywhere!
    Remote Control + Streaming to your iPad? Squeezebox + iPad = SqueezePad
    Want to see a Weather Forecast on your Radio/Touch/Controller ? => why not try my Weather Forecast Applet
    Want to use the Headphones with your Controller ? => why not try my Headphone Switcher Applet

  3. #3
    Senior Member gharris999's Avatar
    Join Date
    Apr 2005
    Location
    Santa Fe, NM
    Posts
    3,299
    Quote Originally Posted by bluegaspode View Post
    3483 UDP is the discovery protocol.
    3483 TCP is SlimProto, the protocol which has all the low level playback and synchronization commands.

    Without 3483 TCP playback won't work.
    Eh. You're right, of course. And my firewall IS already configured to allow TCP on 3483:
    Code:
    # ufw status
    Status: active
    
    To                         Action      From
    --                         ------      ----
    ...
    3483/udp                   ALLOW       192.168.0.0/24
    3483/tcp                   ALLOW       192.168.0.0/24
    9000/tcp                   ALLOW       192.168.0.0/24
    9090/tcp                   ALLOW       192.168.0.0/24
    ...
    So why was I getting those messages, I wonder?

  4. #4
    Senior Member
    Join Date
    May 2005
    Location
    In a house
    Posts
    1,629
    Quote Originally Posted by gharris999 View Post
    Eh. You're right, of course. And my firewall IS already configured to allow TCP on 3483:
    So why was I getting those messages, I wonder?
    These are TCP Reset packets, and are likely due to the connection already being closed, but the remote is late in closing its side. Since the connection is closed, the linux firewall blocks the now invalid connection. I used to see these in my Smoothwall firewall. See:

    http://community.smoothwall.org/foru...ic.php?t=24576

    for an explanation on how to drop the messages.

  5. #5
    Senior Member gharris999's Avatar
    Join Date
    Apr 2005
    Location
    Santa Fe, NM
    Posts
    3,299
    Ok, that makes total sense. I suppose that if one were to stop squeezeboxserver, the squeezebox may very well continue to send tcp traffic on 3483...and the firewall would complain. Thanks.

  6. #6
    Senior Member
    Join Date
    May 2005
    Location
    In a house
    Posts
    1,629
    They should cease. These would only be related to recently closed (no longer established) connections. They are not unsolicited - just one side finished the close handshake early. Typically, both sides ack the close.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •