OK, I tired the GB lite forum and had no responses, so I'll try this.I have two work stations set up on the protected GB Lite 3.0.3 interface. One is left on, but goes into a standby type mode after some period of time. The other is only on when it is in use, otherwise it is shut off. I have had this set-up running for about two months with no problems. Recently, I noticed that the WS which is left on seems to be responsible for the following alarm, veery 15 minutes: 16 5 Jul 10 21:16:35 NAT: Open UDP [192.168.XX.XX/137]->[24.147.YYY.YYY/10629]->[24.128.ZZZ.ZZZ/53]. 16 5 Jul 10 21:16:56 NAT: Close UDP [192.168.XX.XX/137]->[24.147.YYY.YYY/10629]->[24.128.ZZZ.ZZZ/53] Pkts 1 1, Bytes 62 128.
The 24.147.YYY.YYY happens to be the IP address assigned to my external NIC by the ISP through DCHP (cable modem). The 24.128.ZZZ.ZZZ is one of the DNS servers at the ISP. I know 137 is a NetBios port and 53 is DNS. The port number after the 24.147.YYY.YYY is incrementing by one every 15 minutes. Does any one know, do I have a Trojan inside this WS? The two workstations are set-up in a Windows '98 workgroup so files can be shared between them - does this have something to do with the messages? I don't think I have a serious problem, but don't remember seeing this the first couple of weeks I had GB up and running. Also, I've never used anything but the default filter set-up right 'out of the box'. Any information would be appreciated. Thanks. Bruce S. ____________________________________________________________________ Get free email and a permanent address at http://www.netaddress.com/?N=1
