Re: Prelude and Firewalls...

From: Goldenpi (goldenpi@softhome.net)
Date: 03/02/03


From: "Goldenpi" <goldenpi@softhome.net>
Date: Sun, 02 Mar 2003 07:40:15 GMT


"joe blow" <hoe@ho.com> wrote in message
news:p9L6a.80247$na.1630424@news2.calgary.shaw.ca...
> I recently installed the Linux MNF firewall. Its been great in the way it
> works. One of the things that I have come accross lately in the prelude
> logs is udp scan attacks from my own ISP. udp ports ranging from 1101 to
> 11136
>
> When I asked the ISP to explain. They stated it was thier dhcp server
> trying to see if the server was still alive.
>
> I have never heard of DHCP using port scans to see if a server is alive
> before. Also, why only recently.
>
> If anyone can offer some insite it would be greatly appreciated.
>
> Thank you,

Whatever causes those, its not the DHCP server. Not unless someone programed
it really badly at least, and couldn't be bothered to look up code for ICMP
ECHO packets :-). Possibly the ISP is monitoring p2p usage, a lot if ISPs
dont like it. Cant think of any other reasons.

>
> Shawn Belcourt
> shawn_belcourt@wssl.com
> Warner Shelter Systems Limited
> Calgary, Alberta
>
>
>



Relevant Pages

  • Re: OT: Wireless Home Network
    ... > access, the DHCP server is located at the ISP's facility, and not is ... ISP to a block of local addresses. ... they undergo NAT translation will they reach the outside, ...
    (rec.crafts.metalworking)
  • Re: two pf questions
    ... Below is my pf.conf ruleset. ... For the dhcp server for my isp being on ... pass out on $ext_if proto tcp all modulate state flags S/SA ...
    (comp.unix.bsd.openbsd.misc)
  • Re: DHCP lease question
    ... > advantage in that if I change my kit the ISP does not have to do anything. ... So youa re tellign me that in case of static ip assignement we ... it could well be your router remembering what address it had ... It might as well be the isp's dhcp server the remembers what i had uses ...
    (comp.security.firewalls)
  • Re: Prelude and Firewalls...
    ... > I recently installed the Linux MNF firewall. ... > logs is udp scan attacks from my own ISP. ... udp ports ranging from 1101 to ... its not the DHCP server. ...
    (comp.security.firewalls)
  • Re: Port Scans and Prelude
    ... Shawn Belcourt wrote: ... > I recently installed the Linux MNF firewall. ... udp ports ranging from 1101 to ... Which system from your ISP? ...
    (comp.os.linux.security)