Hello:
After changing my ISP service from ISDN to a T1 line, I see a lot more 'poking around' activity. On my logfile, I see a series of attempts to connect to inactive IP addresses and ports(80,25,21) every 3-5 seconds for about 30 minutes. This is repeated for different IP addresses assigned to us but not yet in service. I suspect this happens also for legit addresses/ports but Gnatbox does not log them as my filters are set for 'nolog'. This pattern happens several times during the day/night. Connecting IP addresses are usually untraceable. Are these 'script kiddies' out there flexing their wings or just my imagination? I am glad my GB-100 is working fine. BTW, how can I recognize a DOS attack from logs? Suresh Ganu
