Frequnt port scan attacks

The past few days I've been getting multiple 'port scan attack logged' notices from my Sygate Personal Firewall (version not indicated in doc). This is unusual. Anyone else seeing this or is someone going through my ISP's (Nationwide) IP list? Usually I only get a few a week - now I'm getting a few an hour.

Strange. Comments?

Reply to
Ken Knecht
Loading thread data ...

This is not unusual, this is rather what should be expected.

Seeing what? So far there's no indication of any network-related activity. Your error-simulation software simply simulated an error, that's all.

Reply to
Sebastian G.

If you get a NAT router with logging, the traffic would be blocked, and the PFW/Sygate running on the computer would never react to the blocked traffic the router is blocking in front of the machine.

formatting link

Reply to
Mr. Arnold

It's not at all unusual to see port scan attempts from the internet. We get thousands of failed attempts every day on our publicly facing IP network and they are all blocked and logged. You don't mention what type of internet connection you have, but assume you have a DSL/ADSL/Cable type connection with a DHCP assigned IP address. It is not at all unlikely that you recently updated your IP address with your ISP and the port scans you are seeing are related to the previous user of that IP address. There are many other reasons this could be occurring as well, you would need to provide more specific information such as the source IP addresses, ports, and protocols being used, number and frequency of scans from the same address, etc... in order to determine anything more than you are seeing normal internet traffic.

Reply to
Default User

what do you mean with that last paragraph?

Reply to
goarilla

keep in mind that lots of (default configured) firewalls, IDS systems generate what can be called false positives. Unless you have knowledge of how nmap, the de facto portscanner in the world works, and how that relates to your firewall logs and settings you can practically ignore these logs since you have no clue what they are doing, how they are doing and why?

Reply to
goarilla

"Sygate Personal Firewall", as the name says, is a "personal firewall", whichs supposed functionality to create random network errors (obvious when looking at the design implementation).

Reply to
Sebastian G.

aaah so you are just disgusted by third party (crap - oxymoron ?) windows personal firewalls so much you call them error-simulation software. :D

Reply to
goarilla

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.