Sonicwall "possible port scan" Help!



Hi all,

Our office has a SonicWall TZ 170 firewall that is setup to send
attempted attacks and regular event logs to my email address.

I routinely receive a dozen or so notices a day that seem relatively
benign (unhandled packets and such). About 5 days ago, I began
receiving emails by the hundreds a day! They are all as follows:

05/21/2007 08:35:28.464 - Probable port scan dropped -
67.185.175.xxx, 58610, WAN - 70.147.xxx.xxx, 32793, WAN - TCP
scanned port list, 1275, 20329, 16091, 14817, 12963, 1233, 55485,
36531, 53375, 13247

The second IP address listed is our IP address. I don't recognize the
first IP address, but it is always one of two different IP addresses.
The port numbers change every time. Any idea what is causing this and
why it just started recently?

It is entirely possible that some of the employees have installed new
software on their machines, but I am positive that no one has recently
altered the firewall settings (I have the only access, but have not
used it in months).

I'm new to firewall's and servers so please bear with me. Thanks in
advance for the help!

Nate

.



Relevant Pages