UFW blocked connection, what is this connection?

Quick to answer questions about finding your way around Linux Mint as a new user.
Forum rules
There are no such things as "stupid" questions. However if you think your question is a bit stupid, then this is the right place for you to post it. Stick to easy to-the-point questions that you feel people can answer fast. For long and complicated questions use the other forums in the support section.
Before you post read how to get help. Topics in this forum are automatically closed 6 months after creation.
Locked
XILNU
Level 1
Level 1
Posts: 26
Joined: Tue Jan 30, 2018 12:57 pm

UFW blocked connection, what is this connection?

Post by XILNU »

Hello! Can you think reason why Windows 10 laptop has tried to reach Mint PC? They are using same router to connect internet. If i understood correctly destination port in Mint system is 2054. Which is according to Internet "Weblogin Port". There seems to be quite a spam about this [UFW BLOCK] in log files.
And how to stop this, not just hide its existence :)

Code: Select all

Aug 26 18:27:27 hostname kernel: [37880.574240] [UFW BLOCK] IN=IN OUT= MAC=MAC SRC=192.168.0.188 DST=192.168.0.183 LEN=56 TOS=0x00 PREC=0x00 TTL=128 ID=60242 PROTO=UDP SPT=61938 DPT=2054 LEN=36 
Aug 26 18:28:27 hostname kernel: [37940.583915] [UFW BLOCK] IN=IN OUT= MAC=MAC SRC=192.168.0.188 DST=192.168.0.183 LEN=56 TOS=0x00 PREC=0x00 TTL=128 ID=60243 PROTO=UDP SPT=53864 DPT=2054 LEN=36 
Aug 26 18:29:27 hostname kernel: [38000.590827] [UFW BLOCK] IN=IN OUT= MAC=MAC SRC=192.168.0.188 DST=192.168.0.183 LEN=56 TOS=0x00 PREC=0x00 TTL=128 ID=60244 PROTO=UDP SPT=49845 DPT=2054 LEN=36 
Aug 26 18:30:27 hostname kernel: [38060.591316] [UFW BLOCK] IN=IN OUT= MAC=MAC SRC=192.168.0.188 DST=192.168.0.183 LEN=56 TOS=0x00 PREC=0x00 TTL=128 ID=60245 PROTO=UDP SPT=49846 DPT=2054 LEN=36 
Aug 26 18:31:27 hostname kernel: [38120.605356] [UFW BLOCK] IN=IN OUT= MAC=MAC SRC=192.168.0.188 DST=192.168.0.183 LEN=56 TOS=0x00 PREC=0x00 TTL=128 ID=60246 PROTO=UDP SPT=49847 DPT=2054 LEN=36 
Aug 26 18:32:27 hostname kernel: [38180.614568] [UFW BLOCK] IN=IN OUT= MAC=MAC SRC=192.168.0.188 DST=192.168.0.183 LEN=56 TOS=0x00 PREC=0x00 TTL=128 ID=60247 PROTO=UDP SPT=49848 DPT=2054 LEN=36 
Aug 26 18:33:27 hostname kernel: [38240.617186] [UFW BLOCK] IN=IN OUT= MAC=MAC SRC=192.168.0.188 DST=192.168.0.183 LEN=56 TOS=0x00 PREC=0x00 TTL=128 ID=60248 PROTO=UDP SPT=49849 DPT=2054 LEN=36 
Aug 26 18:34:27 hostname kernel: [38300.623785] [UFW BLOCK] IN=IN OUT= MAC=MAC SRC=192.168.0.188 DST=192.168.0.183 LEN=56 TOS=0x00 PREC=0x00 TTL=128 ID=60249 PROTO=UDP SPT=49850 DPT=2054 LEN=36 
Aug 26 18:35:27 hostname kernel: [38360.635553] [UFW BLOCK] IN=IN OUT= MAC=MAC SRC=192.168.0.188 DST=192.168.0.183 LEN=56 TOS=0x00 PREC=0x00 TTL=128 ID=60250 PROTO=UDP SPT=50529 DPT=2054 LEN=36 
Aug 26 18:36:27 hostname kernel: [38420.665927] [UFW BLOCK] IN=IN OUT= MAC=MAC SRC=192.168.0.188 DST=192.168.0.183 LEN=56 TOS=0x00 PREC=0x00 TTL=128 ID=60251 PROTO=UDP SPT=55321 DPT=2054 LEN=36 
Aug 26 18:37:27 hostname kernel: [38480.667677] [UFW BLOCK] IN=IN OUT= MAC=MAC SRC=192.168.0.188 DST=192.168.0.183 LEN=56 TOS=0x00 PREC=0x00 TTL=128 ID=60252 PROTO=UDP SPT=49834 DPT=2054 LEN=36 
Aug 26 18:38:27 hostname kernel: [38540.667891] [UFW BLOCK] IN=IN OUT= MAC=MAC SRC=192.168.0.188 DST=192.168.0.183 LEN=56 TOS=0x00 PREC=0x00 TTL=128 ID=60253 PROTO=UDP SPT=49835 DPT=2054 LEN=36 
Aug 26 18:39:27 hostname kernel: [38600.674683] [UFW BLOCK] IN=IN OUT= MAC=MAC SRC=192.168.0.188 DST=192.168.0.183 LEN=56 TOS=0x00 PREC=0x00 TTL=128 ID=60254 PROTO=UDP SPT=58027 DPT=2054 LEN=36 
Aug 26 18:40:27 hostname kernel: [38660.689475] [UFW BLOCK] IN=IN OUT= MAC=MAC SRC=192.168.0.188 DST=192.168.0.183 LEN=56 TOS=0x00 PREC=0x00 TTL=128 ID=60255 PROTO=UDP SPT=58028 DPT=2054 LEN=36 
Aug 26 18:41:27 hostname kernel: [38720.692966] [UFW BLOCK] IN=IN OUT= MAC=MAC SRC=192.168.0.188 DST=192.168.0.183 LEN=56 TOS=0x00 PREC=0x00 TTL=128 ID=60256 PROTO=UDP SPT=59388 DPT=2054 LEN=36 
Aug 26 18:42:27 hostname kernel: [38780.701778] [UFW BLOCK] IN=IN OUT= MAC=MAC SRC=192.168.0.188 DST=192.168.0.183 LEN=56 TOS=0x00 PREC=0x00 TTL=128 ID=60257 PROTO=UDP SPT=59389 DPT=2054 LEN=36 
Aug 26 18:43:27 hostname kernel: [38840.713275] [UFW BLOCK] IN=IN OUT= MAC=MAC SRC=192.168.0.188 DST=192.168.0.183 LEN=56 TOS=0x00 PREC=0x00 TTL=128 ID=60258 PROTO=UDP SPT=59390 DPT=2054 LEN=36 
Aug 26 18:44:27 hostname kernel: [38900.715815] [UFW BLOCK] IN=IN OUT= MAC=MAC SRC=192.168.0.188 DST=192.168.0.183 LEN=56 TOS=0x00 PREC=0x00 TTL=128 ID=60259 PROTO=UDP SPT=57008 DPT=2054 LEN=36 
Aug 26 18:45:27 hostname kernel: [38960.743459] [UFW BLOCK] IN=IN OUT= MAC=MAC SRC=192.168.0.188 DST=192.168.0.183 LEN=56 TOS=0x00 PREC=0x00 TTL=128 ID=60260 PROTO=UDP SPT=57009 DPT=2054 LEN=36 
Aug 26 18:46:27 hostname kernel: [39020.758230] [UFW BLOCK] IN=IN OUT= MAC=MAC SRC=192.168.0.188 DST=192.168.0.183 LEN=56 TOS=0x00 PREC=0x00 TTL=128 ID=60261 PROTO=UDP SPT=57010 DPT=2054 LEN=36 
Last edited by LockBot on Wed Dec 28, 2022 7:16 am, edited 1 time in total.
Reason: Topic automatically closed 6 months after creation. New replies are no longer allowed.
User avatar
Pjotr
Level 24
Level 24
Posts: 20129
Joined: Mon Mar 07, 2011 10:18 am
Location: The Netherlands (Holland) 🇳🇱
Contact:

Re: UFW blocked connection, what is this connection?

Post by Pjotr »

Practical advice: don't waste time and energy on this, and above all: don't start tinkering. Just silence the spammy UFW log like this:
https://easylinuxtipsproject.blogspot.c ... .html#ID13
(item 13)

My view: as long as UFW does its job well (which it apparently does in your case), it should keep its bloody mouth shut and shouldn't pester the boss with trivialities. :mrgreen:
Tip: 10 things to do after installing Linux Mint 21.3 Virginia
Keep your Linux Mint healthy: Avoid these 10 fatal mistakes
Twitter: twitter.com/easylinuxtips
All in all, horse sense simply makes sense.
User avatar
karlchen
Level 23
Level 23
Posts: 18227
Joined: Sat Dec 31, 2011 7:21 am
Location: Germany

Re: UFW blocked connection, what is this connection?

Post by karlchen »

Hi, XILNU.

As the root cause is your Windows 10 machine, it would be interesting to find out which Windows service (?) / application (?) keeps on trying to connect to target port 2054 on machines in its LAN in intervals of 60 seconds.
You might use Nir Sofer's CurrPorts in order to identify the process name that does.
Maybe something can be / needs to be switched off on the Windows 10 side.
In case this should not be possible without losing any needed functionality you can still silence the Linux Mint ufw logfile.

Regards,
Karl
Image
The people of Alderaan have been bravely fighting back the clone warriors sent out by the unscrupulous Sith Lord Palpatine for 792 days now.
Lifeline
XILNU
Level 1
Level 1
Posts: 26
Joined: Tue Jan 30, 2018 12:57 pm

Re: UFW blocked connection, what is this connection?

Post by XILNU »

:mrgreen: Thanks for the replies! I'm just curious about this and same time little bit cautious. If the laptop has virus, or what else could cause it try "weblogin", though i have no idea is this weblogin for trying to login Mint system or what does it mean? Can i somehow disable this "weblogin" for security reasons? Or do i need it if i don't remote connect? I actually thought Mint system is invisible to the WIndows laptop, but apparently not.... any tips what to change in ufw before.rules to hide Mint from the Windows?

i got that sudo ufw shut up :mrgreen:
missmoondog
Level 5
Level 5
Posts: 746
Joined: Wed Nov 07, 2018 9:17 am

Re: UFW blocked connection, what is this connection?

Post by missmoondog »

personally, i don't know why anyone would even bother having a software firewall running if using a router? haven't had one running on any of my machines in so many years i can't count them.

this is the exact reason why? it's probably nothing more than that goofy windows machine trying to connect to other machine through lan for file sharing like windows always wants to do unless you turn it off.
XILNU
Level 1
Level 1
Posts: 26
Joined: Tue Jan 30, 2018 12:57 pm

Re: UFW blocked connection, what is this connection?

Post by XILNU »

^Thanks for the reply!

:mrgreen: Im hopeless with Windows 10. and thats not my laptop, but it seems that File and Printer sharing is off, so is Network Discovery.
Anyway this is about Mint, so any tips to previous questions i had? :)

I suppose there is an option somewhere in router's settings how to block connection to another computer. Just im not so good with the router things. I know router's firewall is on but it seems not to block these lan things atm.
User avatar
smurphos
Level 18
Level 18
Posts: 8498
Joined: Fri Sep 05, 2014 12:18 am
Location: Irish Brit in Portugal
Contact:

Re: UFW blocked connection, what is this connection?

Post by smurphos »

Is the windows machine running Mcafee?

https://superuser.com/questions/987494/ ... -behaviour
For custom Nemo actions, useful scripts for the Cinnamon desktop, and Cinnamox themes visit my Github pages.
XILNU
Level 1
Level 1
Posts: 26
Joined: Tue Jan 30, 2018 12:57 pm

Re: UFW blocked connection, what is this connection?

Post by XILNU »

^ Thanks fort that!
The Windows machine indeed has McAfee, so there might be something in that, but it's totally
alien software to me. I didnt catch by first reading what was the key in there, a McAfee's setting perhaps.

So probably i can just shut the to UFW silent, or i'd like more stealth this Mint machine
from the WIndows system. Which i thought i already had done...but it isn't it seems.
User avatar
smurphos
Level 18
Level 18
Posts: 8498
Joined: Fri Sep 05, 2014 12:18 am
Location: Irish Brit in Portugal
Contact:

Re: UFW blocked connection, what is this connection?

Post by smurphos »

It looks like it's a McAfee windows service that's the culprit, some Home Network Protect function, that according to the last commentator tries to identify vulnerabilities on other machines on the LAN.

UFW is doing its job, the windows box is probably sending these requests to every IP on the LAN, but your Linux box is ignoring them. If the Windows machine isn't yours just turn off UFW logging.

If the router is yours I guess you could probably tweak it's settings to block these requests at that level.
For custom Nemo actions, useful scripts for the Cinnamon desktop, and Cinnamox themes visit my Github pages.
XILNU
Level 1
Level 1
Posts: 26
Joined: Tue Jan 30, 2018 12:57 pm

Re: UFW blocked connection, what is this connection?

Post by XILNU »

Thanks for the reply!

It seems i'm not able to block that probing/scanning on router level.
I created an ip block rule for the laptop but it seems it isn't effective on lan.
My Mint is still blocking these knockings.

So i just need to live with it. Thanks for the replies again! :)
polarvortex

Re: UFW blocked connection, what is this connection?

Post by polarvortex »

If you have a router that has VLAN capability then I think you could keep the two computers in different VLANs so they couldn't communicate. Similarly, on wifi you could put the windows computer on the guest wifi and set your guest wifi to be isolated.
User avatar
Pippin
Level 4
Level 4
Posts: 441
Joined: Wed Dec 13, 2017 11:14 am
Location: The Shire

Re: UFW blocked connection, what is this connection?

Post by Pippin »

So the concern is log spam?
If so, create a rule on Mint allowing that traffic or block it in Windows Firewall.
XILNU wrote: Sun Sep 01, 2019 5:30 am It seems i'm not able to block that probing/scanning on router level.
A router is not involved in traffic on the same subnet.
I gloomily came to the ironic conclusion that if you take a highly intelligent person and give them the best possible, elite education, then you will most likely wind up with an academic who is completely impervious to reality.
Halton Arp
Locked

Return to “Beginner Questions”