[10192947.300008] UDP: bad checksum. From 1.2.3.4:10398 to 3.4.5.6:5060 ulen 237
I started getting some of this yesterday on one host.
I think that there is a way to use regex and fail2ban to block flood attacks like this. Does anyone have the recipe?
It comes in on various ports. This example is port 5060 but the host does not have anything listening there.