Tony this is someone actively trying to get in to your server through port69... unless this is one of YOUR IP addies. Is it always the same IP addy? PortSentry is doing what it is supposed to - it's monitoring your ports for scanners and attempts to get in; and then tossing the IP address of those people into the hosts.deny file. (So the next time they try scanning, you are more or less 'invisible' to them.) Be patient. You'll get used to the logs soon enough - but even after weeks of having them your paranoia won't lessen any, trust me. :)
Carrie/everyone,The IP address is 192.168.1.1 - isn't this a reserved IP address for a local IP network? I thought it might be the Cobalt "talking to itself" - maybe something to do with the active monitoring etc.?
What about the other log entry, every 15 minutes that I get: Feb 20 10:15:03 www sendmail[1153]: NOQUEUE: localhost [127.0.0.1] did not issue MAIL/EXPN/VRFY/ETRN during connection to MTA Any help gratefully recieved! Tony _________________________________________________________________________ Get Your Private, Free E-mail from MSN Hotmail at http://www.hotmail.com.