RE: ISA Server port scan attack - servers own external ipaddress

"James C Slora Jr" <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
Mueller, Eric wrote Tuesday, January 11, 2005 13:06

> ISA Server detected a well-known port scan attack from 
> Internet Protocol
> (IP) address 192.168.1.252. A well-known port is any port in 
> the range of 1-2048. For more information about this event, 
> see ISA Server Help.
> 
> This ip address in these message alerts is binded to the 
> external NIC of the ISA Server. Has anyone experienced this 
> or has heard of this?

You can get these alerts from routine outbound traffic that hits a site
multiple times very quickly (such as when loading a web page).

Check your outbound proxy and firewall logs around the time of the alert.
The logs will show whether you have a portscanning or infection problem, or
just an alert threshold problem. Default threshold for portscanning is
pretty aggressive. You will have to trade off between getting more
occasional false alarms, and missing more actual portscans (if you truly
care about them).

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.