[TriLUG] Port Scans on your firewalls?

James Brigman jbrigman at nc.rr.com
Wed Mar 23 17:00:00 EST 2005


Hey guys;

How's service for you guys with time warner cable in the Raleigh area?
I'm having a little bit of trouble with port scans coming from a
particular host. Here's what the log entry looks like:

Wed, 03/23/2005 13:53:05 - TCP connection dropped - Source:24.88.87.240,
3307, WAN - Destination:24.88.248.163, 80, LAN - 'Possible Port Scan'

I'm getting lots of these all day long. Does 24.88.87.240 ring a bell
with anyone? Are there any defensive measures I can take with a basic
firmware firewall? Would rolling my own Linux firewall give me any good
options for warding off these port scans?

JKB





More information about the TriLUG mailing list