Hi,
> What I found in the logs was a series of connections rising from source
port
> 1024 and destination port 33434 to source port 1113 and destination port
> 33523. These connections were from our router to our firewall.
Those are exactly the UDP ports used by the Van Jacobsen-implementation of
traceroute (=most common UNIX-implementation).
Maybe somebody just tracerouted your FW. (But then I don't understand why
the packets originated from the router...)
Do you filter out UDP and ICMP traffic on your router?
Enno Rey
[EMAIL PROTECTED]
PGP 192E 3EBC AD7D DA41 82FC 0C21 5013 0A2C 42B9 F190
-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]