UDP port 53 is DNS lookups. Someone is probably just looking for some
unadvertised DNS info :)
Tom Reynolds, MCSE, CCNA
_________________________
Pilgrim Baxter and Associates
Network Security and Engineering
825 Duportail Rd.
Wayne, Pennsylvania 19087-5525
610-578-1581
[EMAIL PROTECTED]
-----Original Message-----
From: Langa Kentane [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, January 09, 2001 7:34 AM
To: Firewall-1 Mailing List (E-mail)
Subject: [FW1] possible port scan?
I noticed on my logs today that someone was trying to connect to our
firewall, the ports range from 34xxx to 37xxx, in random order. The source
port is udp 53 on all of them. The packets are getting dropped on the
stealth rule. What could this be?
__________________________________________________________
Langa Kentane | TEL: (011) 290 3218
Security Administrator | Cell: 082 606 1515
DISCOVERY HEALTH | http://www.discoveryhealth.co.za
__________________________________________________________________
============================================================================
====
To unsubscribe from this mailing list, please see the instructions at
http://www.checkpoint.com/services/mailing.html
============================================================================
====
================================================================================
To unsubscribe from this mailing list, please see the instructions at
http://www.checkpoint.com/services/mailing.html
================================================================================