Traffic from port 25 to high ports?

From: Matt Simonsen (matt_lists@careercast.com)
Date: 09/27/01


Message-ID: <3BB35240.6060603@careercast.com>
Date: Thu, 27 Sep 2001 09:22:24 -0700
From: Matt Simonsen <matt_lists@careercast.com>
To: security-basics@securityfocus.com
Subject: Traffic from port 25 to high ports?

I am seeing traffic regularly coming from remote servers' port 25
destined to our servers' high ports, generally in the 1-3k range. Is
this normal? I plan to block it all, from what I understand SMTP goes
only from 25 to 25, but if that's the case I can't figure out what this
would be.

According to our IPFilter logs the traffic generally has -AFP set,
please let me know off-line if a tidbit of info I could provide can help
you answer my question.

Thanks
Matt Simonsen