I'm facing with this issue in Ubuntu server with UFW.
There are my UFW configuration
Status: activeLogging: on (low)Default: deny (incoming), allow (outgoing), disabled (routed)New profiles: skipTo Action From-- ------ ----22 ALLOW IN Anywhere 22/tcp (OpenSSH) ALLOW IN Anywhere 22/tcp ALLOW IN Anywhere 6414/tcp ALLOW IN Anywhere 80 ALLOW IN Anywhere 443 ALLOW IN Anywhere 6414 ALLOW IN Anywhere 22 (v6) ALLOW IN Anywhere (v6) 22/tcp (OpenSSH (v6)) ALLOW IN Anywhere (v6) 22/tcp (v6) ALLOW IN Anywhere (v6) 6414/tcp (v6) ALLOW IN Anywhere (v6) 80 (v6) ALLOW IN Anywhere (v6) 443 (v6) ALLOW IN Anywhere (v6) 6414 (v6) ALLOW IN Anywhere (v6)
I have allowed port tcp 6414, but sometime I check log in /var/log/ufw.log, there is still have log [UFW BLOCK] ... ... DPT=6414
Example:
Aug 14 14:40:44 server kernel: [609497.779453] [UFW BLOCK] IN=enp2s0 OUT= MAC=74:56:3c:28:b9:b2:00:26:98:15:f9:41:08:00 SRC=42.96.33.23 DST=43.229.151.172 LEN=40 TOS=0x00 PREC=0x00 TTL=118 ID=14171 DF PROTO=TCP SPT=50139 DPT=6414 WINDOW=1025 RES=0x00 ACK FIN URGP=0 Aug 14 14:41:05 server kernel: [609518.766160] [UFW BLOCK] IN=enp2s0 OUT= MAC=74:56:3c:28:b9:b2:00:26:98:15:f9:41:08:00 SRC=42.96.33.23 DST=43.229.151.172 LEN=40 TOS=0x00 PREC=0x00 TTL=118 ID=17477 DF PROTO=TCP SPT=50140 DPT=6414 WINDOW=0 RES=0x00 ACK RST URGP=0 Aug 14 14:41:23 server kernel: [609537.131108] [UFW BLOCK] IN=enp2s0 OUT= MAC=74:56:3c:28:b9:b2:00:26:98:15:f9:41:08:00 SRC=103.163.118.153 DST=43.229.151.172 LEN=40 TOS=0x00 PREC=0x00 TTL=114 ID=25481 DF PROTO=TCP SPT=60035 DPT=6414 WINDOW=65280 RES=0x00 ACK FIN URGP=0 Aug 14 14:41:42 server kernel: [609556.200291] [UFW BLOCK] IN=enp2s0 OUT= MAC=74:56:3c:28:b9:b2:00:26:98:15:f9:41:08:00 SRC=103.188.244.144 DST=43.229.151.172 LEN=40 TOS=0x00 PREC=0x00 TTL=118 ID=12780 DF PROTO=TCP SPT=55462 DPT=6414 WINDOW=0 RES=0x00 ACK RST URGP=0 Aug 14 14:42:02 server kernel: [609576.038161] [UFW BLOCK] IN=enp2s0 OUT= MAC=74:56:3c:28:b9:b2:00:26:98:15:f9:41:08:00 SRC=103.188.244.144 DST=43.229.151.172 LEN=40 TOS=0x00 PREC=0x00 TTL=118 ID=13179 DF PROTO=TCP SPT=55463 DPT=6414 WINDOW=64240 RES=0x00 ACK FIN URGP=0 Aug 14 14:42:22 server kernel: [609596.023258] [UFW BLOCK] IN=enp2s0 OUT= MAC=74:56:3c:28:b9:b2:00:26:98:15:f9:41:08:00 SRC=103.163.118.153 DST=43.229.151.172 LEN=40 TOS=0x00 PREC=0x00 TTL=114 ID=27295 DF PROTO=TCP SPT=60001 DPT=6414 WINDOW=65280 RES=0x00 ACK FIN URGP=0 Aug 14 14:42:43 server kernel: [609616.565354] [UFW BLOCK] IN=enp2s0 OUT= MAC=74:56:3c:28:b9:b2:00:26:98:15:f9:41:08:00 SRC=103.163.118.153 DST=43.229.151.172 LEN=40 TOS=0x00 PREC=0x00 TTL=114 ID=29464 DF PROTO=TCP SPT=59991 DPT=6414 WINDOW=65280 RES=0x00 ACK FIN URGP=0 Aug 14 14:43:02 server kernel: [609636.040257] [UFW BLOCK] IN=enp2s0 OUT= MAC=74:56:3c:28:b9:b2:00:26:98:15:f9:41:08:00 SRC=103.188.244.144 DST=43.229.151.172 LEN=40 TOS=0x00 PREC=0x00 TTL=118 ID=15641 DF PROTO=TCP SPT=55463 DPT=6414 WINDOW=0 RES=0x00 ACK RST URGP=0 Aug 14 14:43:24 server kernel: [609657.358097] [UFW BLOCK] IN=enp2s0 OUT= MAC=74:56:3c:28:b9:b2:00:26:98:15:f9:41:08:00 SRC=103.163.118.153 DST=43.229.151.172 LEN=40 TOS=0x00 PREC=0x00 TTL=114 ID=1974 DF PROTO=TCP SPT=60050 DPT=6414 WINDOW=65280 RES=0x00 ACK FIN URGP=0 Aug 14 14:43:42 server kernel: [609676.055795] [UFW BLOCK] IN=enp2s0 OUT= MAC=74:56:3c:28:b9:b2:00:26:98:15:f9:41:08:00 SRC=103.65.235.57 DST=43.229.151.172 LEN=40 TOS=0x00 PREC=0x00 TTL=118 ID=23870 DF PROTO=TCP SPT=51122 DPT=6414 WINDOW=515 RES=0x00 ACK FIN URGP=0 Aug 14 14:44:03 server kernel: [609696.339282] [UFW BLOCK] IN=enp2s0 OUT= MAC=74:56:3c:28:b9:b2:00:26:98:15:f9:41:08:00 SRC=103.65.235.238 DST=43.229.151.172 LEN=40 TOS=0x00 PREC=0x00 TTL=119 ID=8837 DF PROTO=TCP SPT=53797 DPT=6414 WINDOW=0 RES=0x00 RST URGP=0 Aug 14 14:44:22 server kernel: [609716.028639] [UFW BLOCK] IN=enp2s0 OUT= MAC=74:56:3c:28:b9:b2:00:26:98:15:f9:41:08:00 SRC=103.65.235.57 DST=43.229.151.172 LEN=40 TOS=0x00 PREC=0x00 TTL=118 ID=3165 DF PROTO=TCP SPT=51121 DPT=6414 WINDOW=515 RES=0x00 ACK FIN URGP=0 Aug 14 14:44:44 server kernel: [609737.298201] [UFW BLOCK] IN=enp2s0 OUT= MAC=74:56:3c:28:b9:b2:00:26:98:15:f9:41:08:00 SRC=103.65.235.57 DST=43.229.151.172 LEN=40 TOS=0x00 PREC=0x00 TTL=119 ID=9273 DF PROTO=TCP SPT=50764 DPT=6414 WINDOW=0 RES=0x00 RST URGP=0 Aug 14 14:45:14 server kernel: [609767.864047] [UFW BLOCK] IN=enp2s0 OUT= MAC=74:56:3c:28:b9:b2:00:26:98:15:f9:41:08:00 SRC=103.65.235.57 DST=43.229.151.172 LEN=40 TOS=0x00 PREC=0x00 TTL=119 ID=17560 DF PROTO=TCP SPT=51129 DPT=6414 WINDOW=515 RES=0x00 ACK FIN URGP=0 Aug 14 14:45:23 server kernel: [609776.890024] [UFW BLOCK] IN=enp2s0 OUT= MAC=74:56:3c:28:b9:b2:00:26:98:15:f9:41:08:00 SRC=103.65.235.57 DST=43.229.151.172 LEN=40 TOS=0x00 PREC=0x00 TTL=119 ID=20262 DF PROTO=TCP SPT=51129 DPT=6414 WINDOW=515 RES=0x00 ACK FIN URGP=0 Aug 14 14:45:50 server kernel: [609803.381515] [UFW BLOCK] IN=enp2s0 OUT= MAC=74:56:3c:28:b9:b2:00:26:98:15:f9:41:08:00 SRC=103.65.235.57 DST=43.229.151.172 LEN=40 TOS=0x00 PREC=0x00 TTL=118 ID=27861 DF PROTO=TCP SPT=51052 DPT=6414 WINDOW=0 RES=0x00 ACK RST URGP=0 Aug 14 14:46:10 server kernel: [609824.169110] [UFW BLOCK] IN=enp2s0 OUT= MAC=74:56:3c:28:b9:b2:00:26:98:15:f9:41:08:00 SRC=103.65.235.57 DST=43.229.151.172 LEN=40 TOS=0x00 PREC=0x00 TTL=119 ID=458 DF PROTO=TCP SPT=51130 DPT=6414 WINDOW=515 RES=0x00 ACK FIN URGP=0 Aug 14 14:46:24 server kernel: [609838.157627] [UFW BLOCK] IN=enp2s0 OUT= MAC=74:56:3c:28:b9:b2:00:26:98:15:f9:41:08:00 SRC=103.65.235.57 DST=43.229.151.172 LEN=40 TOS=0x00 PREC=0x00 TTL=119 ID=4708 DF PROTO=TCP SPT=51096 DPT=6414 WINDOW=0 RES=0x00 ACK RST URGP=0
What should I do with this one?
I'm expecting UFW no block any package coming port which are allowed.