Need some help figuring this out

Ok so every 5 mins something is trying to communicate with an ip address (69.42.215.252) but it seems like it is coming from my ipfire box itself. Ive watched on tshark and dont see this ip address show up at all in the logs

EDIT: this is happening when /usr/bin/ddns update-all is kicking off at 5 min intervals

anyone know how to exclude this from the drop hostile entries?


thanks
siosios

Your DDNS provider is freedns.afraid.org

This issue has been covered in another post thread earlier today and also back on 10th March.

The post from earlier today is

https://community.ipfire.org/t/can-i-white-list-one-ip-so-it-do-not-get-drop-hostile/11535

and it has a link to the post thread from 10th March.

Those give more details and to prevent a third post thread running I will close this post. Please use the one from earlier today.

2 Likes