Hi there!
It began yesterday. My W2K-Server (with Zonealarm) reports:
Zonealarm has blocked internet access to your computer.
But this cannot be! In all the years I never got this message because my ASL doesn't forward unrequested packets from outside to inside.
In the ZA log I can find:
2006/06/28 11:22:38 UDP 192.168.2.100:53->192.168.2.20:1048
2006/06/28 11:22:48 UDP 192.168.2.100:53->192.168.2.20:1049
2006/06/28 11:23:14 UDP 192.168.2.100:53->192.168.2.20:1050
2006/06/28 11:23:24 UDP 192.168.2.100:53->192.168.2.20:1051
2006/06/28 11:23:34 UDP 192.168.2.100:53->192.168.2.20:1052
2006/06/28 11:23:44 UDP 192.168.2.100:53->192.168.2.20:1053
2006/06/28 11:23:14 UDP 192.168.2.100:53->192.168.2.20:1054
2006/06/28 11:23:24 UDP 192.168.2.100:53->192.168.2.20:1055
This is very strange, because
192.168.2.100 is the internal address of my ASL.
192.168.2.20 is the internal address of my W2K-Server.
The odd thing is, that the target port is counting up and that my firewall obviously tries to access one of my computers via DNS..!? What's going in here?
Luckily, I was on my server when this happened and I immediately logged in my ASL. In the moment when I disabled the DNS-Proxy in the ASL, the warnings from Zonealarm stopped.
Because I had still installed ASL4, I thought that this was maybe caused by a security leak. So I wiped the whole FW harddisk and installed a fresh ASL6.
Everything was fine, until now:
2006/06/29 01:26:28 UDP 192.168.2.100:53->192.168.2.20:3943
2006/06/29 01:26:38 UDP 192.168.2.100:53->192.168.2.20:3945
2006/06/29 03:27:06 UDP 192.168.2.100:53->192.168.2.20:3954
2006/06/29 03:27:16 UDP 192.168.2.100:53->192.168.2.20:3956
2006/06/29 05:27:36 UDP 192.168.2.100:53->192.168.2.20:3964
2006/06/29 05:27:46 UDP 192.168.2.100:53->192.168.2.20:3965
2006/06/29 07:28:14 UDP 192.168.2.100:53->192.168.2.20:3974
2006/06/29 07:28:24 UDP 192.168.2.100:53->192.168.2.20:3975
[...]
Here I can see 2 things: There is a thing that happens every 10 seconds, but always around the 23 minute of an hour (counting up, 23, 24, 25,... as you can see).
What can this be?
I'm totally clueless.
Thanks in advance.
... Tobias
This thread was automatically locked due to age.