OK, I tired the GB lite forum and had no responses, so I'll try this.I have
two work stations set up on the protected GB Lite 3.0.3 interface. One is left
on, but goes into a standby type mode after some period of time. The other is
only on when it is in use, otherwise it is shut off. I have had this set-up
running for about two months with no problems.
Recently, I noticed that the WS which is left on seems to be responsible for
the following alarm, veery 15 minutes:
16 5 Jul 10 21:16:35 NAT: Open UDP
[192.168.XX.XX/137]->[24.147.YYY.YYY/10629]->[24.128.ZZZ.ZZZ/53].
16 5 Jul 10 21:16:56 NAT: Close UDP
[192.168.XX.XX/137]->[24.147.YYY.YYY/10629]->[24.128.ZZZ.ZZZ/53] Pkts 1 1,
Bytes 62 128.

The 24.147.YYY.YYY happens to be the IP address assigned to my external NIC by
the ISP through DCHP (cable modem). The 24.128.ZZZ.ZZZ is one of the DNS
servers at the ISP. I know 137 is a NetBios port and 53 is DNS. The port
number after the 24.147.YYY.YYY is incrementing by one every 15 minutes.

Does any one know, do I have a Trojan inside this WS? The two workstations are
set-up in a Windows '98 workgroup so files can be shared between them - does
this have something to do with the messages?

I don't think I have a serious problem, but don't remember seeing this the
first couple of weeks I had GB up and running. Also, I've never used anything
but the default filter set-up right 'out of the box'.

Any information would be appreciated. Thanks.

Bruce S.



____________________________________________________________________
Get free email and a permanent address at http://www.netaddress.com/?N=1

Reply via email to