Hello, I see on the log of a linux box a lot of tcp connection from port 20 of an other box to various port on my box (generally they are consequential). I don't think they are port scanning because they come from a host that is on official mirror of a web site I host.... But, how to distinguish this kind of activity from a port scan that put the source port = 20. Best regards, mamo - [To unsubscribe, send mail to [EMAIL PROTECTED] with "unsubscribe firewalls" in the body of the message.]
