Been seeing a constant flow of these types packets to multiple hosts I have in a DMZ setup. These hosts are running web servers with only port 80 via packet filters and NAT.
20:54:49 208.169.18.225 27322 -> 172.18.0.86 25 TCP SYN
20:54:52 208.169.18.225 27322 -> 172.18.0.86 25 TCP SYN
20:54:57 216.219.253.238 39930 -> 172.18.0.79 25 TCP SYN
20:54:58 208.169.18.225 27322 -> 172.18.0.86 25 TCP SYN
20:54:59 209.246.228.170 11523 -> 172.18.0.86 25 TCP SYN
20:55:00 199.212.134.4 1177 -> 172.18.0.86 25 TCP SYN
Any clue why? This is coming from a variety of hosts.
This thread was automatically locked due to age.