Linksys Router and BlackICE - Confused!!

From: Beauford (beauford_at_hotpop.com)
Date: 09/24/04


Date: Fri, 24 Sep 2004 08:43:20 -0400

Hi,

I have a Linksys BEFSR41 router with 6 computers connected to it as
outlined below.

Win2000 - Domain Controller and Mail Server - BlackIce installed
Win2000 - Domain Controller and IIS Web Server - BlackIce Installed
XP Pro - Workstation
XP Pro - Workstation
Linux Slackware - Stand alone - Apache webserver running
Windows NT 4.0 - Workstation

I have my Linksys Router set up to forward port 25 traffic to my mail
server and to forward port 80 web traffic to my Linux box.

Since I installed the mail server it is being hammered by these Asian
IP blocks trying to relay through it - so I installed BlackIce to
block this - and that is working fine.

Here's the part where I'm confused. On the other Win2k PC BlackICE is
also picking up traffic to port 25 - and when you look at the logs it
says the victim IP is that of my mail server.

I contacted Linksys and they said this is normal. Well it doesn't seem
normal to me. If port 25 is not being forwarded to this machine then
does it not make sense that this machine should not be seeing any
traffic to this port.

This is what I got from Linksys

"Since the computer is hooked up to the router and the firewall
detects the traffic, even though the port is not forwarded to that
computer, since it is an activity on the router, it would still detect
the traffic for that port but that doesn't mean that it is going
through it."

My understanding was that any traffic that is not forwarded to a
specific machine should be dropped. So BlackICE should never see this
traffic. Am I missing something here.....

Thanks



Relevant Pages

  • Re: Unable to send email from VFP
    ... Is Possible your router is blocking mail traffic? ... try to telnet into your mail server from cmd prompt - ie ... Port is blocked at router ...
    (microsoft.public.fox.programmer.exchange)
  • req help with access-list config
    ... port 110 traffic through the adsl card, ... I know I have to work on the mail server too but I wanted this ... access list restriction in the router. ...
    (comp.dcom.sys.cisco)
  • Re: DoS Attack on UDP port 1434
    ... DMZ with BlackIce. ... I got a couple of attempts on ports 137 and 138 and BlackIce IDS ... Then I got five different attempts on port 1434 by five different IP, ... I tried to get back to the router admin screen -- no way as the machine was ...
    (comp.security.firewalls)
  • Re: bt connection settings - please check im not going mad
    ... IP belonging to a router that is either on your site or on the ISP's. ... then a port 25 request sent to 1.1.1.6. ... sake on the lan as 192.168.0.80 and a seperate machine on the lan ... set up as a mail server could have packets sent to 1.1.1.6 ...
    (uk.telecom.broadband)
  • Re: BlackIce and Router
    ... You say how can he port forward to a DHCP IP issued by the router? ... What is protecting the machine is BlackIce setting there blocking the scans. ...
    (comp.security.firewalls)