[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[cobalt-users] Configure Raq550 Port Scan Detection {Scanned}
- Subject: [cobalt-users] Configure Raq550 Port Scan Detection {Scanned}
- From: "SW" <wppiphoto@xxxxxxxx>
- Date: Wed Mar 24 12:39:01 2004
- Organization: WPPi
- List-id: Mailing list for users to share thoughts on Sun Cobalt products. <cobalt-users.list.cobalt.com>
Can someone help me figure out where I can adjust the Raq550 port scan
detection system. It seems that whenever my Raq550 tries to send an icpm
type 3 to my dns server, I get these notices of a port scan. This is
ligitamite traffic and I want to see how I can specify that any icmp to my
local network is allowed.
BTW, these message are being created from the Raq550 (xxx.xxx.xxx.10) which
is querying my dns server (xxx.xxx.xxx.11)
Here is the port scan notice:
Timestamp: Wed 24 Mar 2004 01:47:14 PM EST
Alert Type: Port Scan Detected
Interface: eth0
Protocol: 3/3/icmp
Packet Size (bytes): 101
Source Address: xxx.xxx.xxx.10
Source port:
Direction: outbound
Destination Address: xxx.xxx.xxx.11
Destination Port:
Log Entry: eth0:portscan: 3/3/icmp xxx.xxx.xxx.10 ->
xxx.xxx.xxx.11 101 (22)
Thanks,
SW
-------------------------------------------------
WPPi.com | WPPi.Net
-------------------------------------------------
http://www.wppi.com | http://www.wppi.net
-------------------------------------------------
WPPi.com & WPPi.Net MailScanner Signature
This message has been scanned for viruses
and dangerous content by WPPi MailScanner,
and has been found to be clean.
-------------------------------------------------