I have just gotten two warnings from my ASL 4.0 box (which has been up for 19 days on this install) that my PDC, an NT4 box which is also my internal DNS, is portscanning other machines on my system. This seems a little funky to me. One alleged scan was from an address on subnet 1 across my VPN to subnet 2, and shows in the log as follows:
Apr 15 15:08:57 (none) kernel: Portscan detected: IN=eth0 OUT=ipsec0 SRC=192.168.X.X DST=192.168.Y.Y LEN=171
TOS=0x00 PREC=0x00 TTL=127 ID=6336 PROTO=UDP SPT=53 DPT=1704 LEN=151
Apr 15 15:08:58 (none) kernel: Portscan
detected: IN=eth0 OUT=ipsec0 SRC=192.168.X.X DST=192.168.Y.Y LEN=129 TOS=0x00 PREC=0x00 TTL=127 ID=7360 PROTO=UDP
SPT=53 DPT=1707 LEN=109
Apr 15 15:08:58 (none) kernel: Portscan detected: IN=eth0 OUT=ipsec0 SRC=192.168.X.X
DST=192.168.Y.Y LEN=171 TOS=0x00 PREC=0x00 TTL=127 ID=8384 PROTO=UDP SPT=53 DPT=1704 LEN=151
Apr 15 15:08:59 (none)
kernel: Portscan detected: IN=eth0 OUT=ipsec0 SRC=192.168.X.X DST=192.168.Y.Y LEN=83 TOS=0x00 PREC=0x00 TTL=127
ID=8640 PROTO=UDP SPT=53 DPT=1707 LEN=63
For the time being I have gone into PSD setup and excluded detection on my own internal network, which should take care of the problem; however, this has never happened before and no configuration changes/software installs/other modifications have been made to either the ASL box or the NT Server in quite some time, so why now?
Dan
This thread was automatically locked due to age.