The past few days I've been getting multiple 'port scan attack logged' notices from my Sygate Personal Firewall (version not indicated in doc). This is unusual. Anyone else seeing this or is someone going through my ISP's (Nationwide) IP list? Usually I only get a few a week - now I'm getting a few an hour.
It's not at all unusual to see port scan attempts from the internet. We get thousands of failed attempts every day on our publicly facing IP network and they are all blocked and logged. You don't mention what type of internet connection you have, but assume you have a DSL/ADSL/Cable type connection with a DHCP assigned IP address. It is not at all unlikely that you recently updated your IP address with your ISP and the port scans you are seeing are related to the previous user of that IP address. There are many other reasons this could be occurring as well, you would need to provide more specific information such as the source IP addresses, ports, and protocols being used, number and frequency of scans from the same address, etc... in order to determine anything more than you are seeing normal internet traffic.
keep in mind that lots of (default configured) firewalls, IDS systems generate what can be called false positives. Unless you have knowledge of how nmap, the de facto portscanner in the world works, and how that relates to your firewall logs and settings you can practically ignore these logs since you have no clue what they are doing, how they are doing and why?