Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Packet Filter Log

Hi,

Please excuse my ignorance with this question, I'm a developer not a network techie.

In the Packet Filter Log I'm constantly getting records such as: (IP addresses have been masked)

4  Default DROP  TCP 
123.43.430.226  :  60112
→ 
72.42.12.43  :  41006

[SYN]  len=48  ttl=118  tos=0x00  srcmac=00:00:00:00:00:00  dstmac=00:24:45c8e:3a:23

I don't recognise either IP address.  How can the source be an IP address outside the network? is this anything to be concerned about? (Apart from my obvious lack of knowledge:confused[:)].

Any advice would be much appriciated.

Many Thanks,
Ian.


This thread was automatically locked due to age.