I'm curious as to when the UTM considers something a port scan. I noticed that for the last 2 days, there is 1 specific UK IP that is slowly scanning ports at my edge. I can tell because if there are 6,126 dropped packets, they are associated to 6,126 services as shown in Logging & Reporting > Network Protection > Firewall. For something to be considered a port scan does it have to be in some more rapid fire manner?
This thread was automatically locked due to age.