Re: [Hampshire] Port scans

Top Page

Reply to this message
Author: Dee Earley
Date:  
To: Hampshire LUG Discussion List
Subject: Re: [Hampshire] Port scans
On 06/12/2009 21:02, Rob Malpass wrote:
> Hi all
> I need a bit of networking advice. Recently my network (or rather
> connection to the internet) has "stalled". By this I mean I'm using
> firefox (admittedly on Vista) and I've noticed that say I'm heading to
> wikipedia - it just times out. If I open another tab sometimes this
> fixes it but on occasion I have had to soft reboot the router.
> On each occasion I've noticed entries in the router log saying:
> **TCP FIN Scan** or
> **SYN Flood to Host**
> with:
> * my local IP address
> * then different ports in the range 62000 to 65000
> * then IP addresses that look reasonable / harmless enough like my mail
> server, my ISP's DNS or Google
> * then port 80 (or sometimes 53) then "ATM1 outbound"
> First question: Is someone just running a port scan? Sounds unlikely as
> it's outbound.
> Second question: If they are - there's nothing I can do about it is there?
> Have I missed anything? One reason I ask is that I'm due for some sort
> of ADSL line upgrade (to the "21st century network") apparently this
> week so was wondering if around the time of changeover things might have
> become a little flaky.


Something is making me think that the nat connection table is full so it
doesn;t recognise the data coming back.
This may be down to a long timeout or LOTS of outgoing connections.

--
Dee Earley (dee@???)

irc:    irc://irc.blitzed.org/
web:    http://www.earlsoft.co.uk
phone:  +44 (0)780 8369596