Sonicwall "possible port scan" Help!
- From: kastnna <kastnna@xxxxxxxxxxxxxx>
- Date: 21 May 2007 07:31:55 -0700
Hi all,
Our office has a SonicWall TZ 170 firewall that is setup to send
attempted attacks and regular event logs to my email address.
I routinely receive a dozen or so notices a day that seem relatively
benign (unhandled packets and such). About 5 days ago, I began
receiving emails by the hundreds a day! They are all as follows:
05/21/2007 08:35:28.464 - Probable port scan dropped -
67.185.175.xxx, 58610, WAN - 70.147.xxx.xxx, 32793, WAN - TCP
scanned port list, 1275, 20329, 16091, 14817, 12963, 1233, 55485,
36531, 53375, 13247
The second IP address listed is our IP address. I don't recognize the
first IP address, but it is always one of two different IP addresses.
The port numbers change every time. Any idea what is causing this and
why it just started recently?
It is entirely possible that some of the employees have installed new
software on their machines, but I am positive that no one has recently
altered the firewall settings (I have the only access, but have not
used it in months).
I'm new to firewall's and servers so please bear with me. Thanks in
advance for the help!
Nate
.
- Follow-Ups:
- Re: Sonicwall "possible port scan" Help!
- From: Moe Trin
- Re: Sonicwall "possible port scan" Help!
- From: RedForeman
- Re: Sonicwall "possible port scan" Help!
- From: RedForeman
- Re: Sonicwall "possible port scan" Help!
- From: mak
- Re: Sonicwall "possible port scan" Help!
- Prev by Date: Re: Automate MAC & HOSTNAME changes in Linksys WRT54G NAT wireless router
- Next by Date: Re: How to block upd port 137 traffic
- Previous by thread: How to block upd port 137 traffic
- Next by thread: Re: Sonicwall "possible port scan" Help!
- Index(es):
Relevant Pages
|
|