Source of closed port RST responses

DAve dave.list at
Sun Dec 20 19:37:34 UTC 2009

I am routinely seeing these entries in one of my servers logs.

Limiting closed port RST response from 373 to 200 packets/sec

The server sits behind a PIX firewall, so I am suspicious of what is
trying to connect to a closed port. I don't see in any other logs what
port is being hit, or what IP is causing these log entries.

Any way to tell what the source IP of these is?


"Posterity, you will know how much it cost the present generation to
preserve your freedom.  I hope you will make good use of it.  If you
do not, I shall repent in heaven that ever I took half the pains to
preserve it." John Adams

More information about the freebsd-questions mailing list