Can anyone offer any insight as to why the other org behind our firewall (they use 10.87.0.0, we use 10.88.0.0) would be slamming our side with attempts at UDP port 161? I don't have many details, other than that there have been over 60,000 attempts in a short period of time. They are mainly to three IPs on our side.
The first question is how do you know this is happening (are you using IDS? your firewall logs? packet sniffer?)?
UDP port 161 is used for SNMP. It's quite common to see large amounts of packets when using SNMP. For example, for a program to get a list of all the SNMP OID's that your router/whatever supports, you'll see several packets for each OID that is supported (and there could be hundreds/thousands of them). So that is probably the equivalent of 1 or several TCP/IP connections (that would instead likely appear as one connection, rather than the thousands of packets that it is comprised of).
-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask for a free 30-day evaluation.
--- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
