Hi all,
We are running FW1 ver 4.1 and running inbound security servers for SMTP,
outbound HTTP and FTP. Lately, we have a lot of connection attempts coming
from internet to the external IP of our firewall using 36121 as service. In
the log file, the entries read:
Action Service Src Dst Rule Src port Info.
drop 36121 a.b.c.d f.w.I.P 4 51564 len 44
reject 36121 a.b.c.d f.w.I.P 0 51564 message
SYNDefender warning: SYN->SYN-ACK->Timeout
This is usually before a SMTP connection to our inbound smtp server.
I've check the port and it doesn't seems to related to any Trojan. Any
advice welcome.
Ken
================================================================================
To unsubscribe from this mailing list, please see the instructions at
http://www.checkpoint.com/services/mailing.html
================================================================================