* David Coulson <41F44FD6.4000205@xxxxxxxxxxxxxxxx> 2005-01-23 20:31
> Thomas Graf wrote:
> >Protocol: 17 (UDP)
> >Checksum: 0x7b08
> >Source: 126.96.36.199 (korean ip)
> >Destination: 10.1.1.5
> > The originator of this packet is likely a BSD based
> >UNIX box. It is unlikely that it dropped to 49 from 128
> >which I think is the base TTL windows uses. Only guessing
> Looks like a DNS packet. AFAIK, 53 is the only UDP port I NAT through
> from the outside to 10.1.1.5. No idea if that really matters or not,
> with respect to the contents of the IP packet.
Yes, this explains the repetive payload. Can you provide your complete
netfilter rule set?