Hi, looking at my Packet Filter Livelog in 1.9, today there are a lot of hits on port 119 (news).
It turns out they are from my ISP's security scanner ( authorized-scan1.security.home.net ); apparently @home has started scanning customers.
Anyways, I'm not running a news server.
What I'm wondering is Why are there so many of these. Each one shows a SYN and a RST.
I believe that I read this is how ASL handles probes, but in PSD, I have it set to DROP/Blackhole.
ISTM that the scanner is getting confused and keeps retrying because of the RST's, and ISTM that DROP would be better.
Also, these hits are NOT showing up in the PSD logs.
Am I making sense?
BTW, the only rule I have for NEWS is to allow DMZ -> any NEWS,
but that is currently not "Aktivated", and if that is affecting this, ISTM that something is wrong as that is for the DMZ outgoing, and shouldn't affect incoming packets.
Thank you,
Barry
09:29:35 24.0.0.203 44026->24.5.13.x 119 TCP SYN
09:29:36 24.0.0.203 44026->24.5.13.x 119 TCP RST
09:29:36 24.0.0.203 44518->24.5.13.x 119 TCP SYN
09:29:37 24.0.0.203 44518->24.5.13.x 119 TCP RST
...
[ 30 July 2001: Message edited by: barrygould ]
This thread was automatically locked due to age.