I received today Portscan detected from 8.8.4.4 (dns.google). Has anyone seen this before?
I am using google servers as dns forwarders.
Thank you,
Martin
This thread was automatically locked due to age.
Got that some times ago, see https://community.sophos.com/products/unified-threat-management/f/german-forum/62491/portscan-detected-google-dns in the German part unfortunately.
A guess from Bob was a spoofed IP. I never had a 100% explanation.
Best regards
Alex
-
Got that some times ago, see https://community.sophos.com/products/unified-threat-management/f/german-forum/62491/portscan-detected-google-dns in the German part unfortunately.
A guess from Bob was a spoofed IP. I never had a 100% explanation.
Best regards
Alex
-
I've learned since then, Alex, that this also can be a DDoS attack where the sending IP is spoofed by devices on a bot net.
Cheers - Bob