Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

What constitutes a port scan?

I'm curious as to when the UTM considers something a port scan. I noticed that for the last 2 days, there is 1 specific UK IP that is slowly scanning ports at my edge. I can tell because if there are 6,126 dropped packets, they are associated to 6,126 services as shown in Logging & Reporting > Network Protection > Firewall. For something to be considered a port scan does it have to be in some more rapid fire manner?



This thread was automatically locked due to age.