I look at my firewall logs on occasion, but don't gather any stats. I probably log close to the same number of denied packets as you have experienced. It's mostly port 137 and 139 stuff which is pretty typical. That NETBios is a noisy protocol. Occasionaly I get someone trying to ftp (which is blocked) or trying to access another one of the common services I don't allow access to. Every now and then I do see someone scanning my ports. Though it doesn't happen often enough for me to worry about it. Makes you realize the importance of a good firewall though. I've found a couple tools on the net that are helpful. If you go to my server at http://franknputer.com you'll see some links there. PCFlank and DSL Reports have some port scanning tools. They target Windows users, but they can be helpful for securing your server as well. Interesting stuff to say the least.
Ok, bye - Craig ----- Original Message ----- From: "James Washer" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Thursday, February 13, 2003 9:12 PM Subject: [RLUG] Firewall logs Do any of you look at your firewall logs very often. Just for fun, I run some stats off of the last three days. I'm averaging 33 attempt per hour to access (blocked) ports on my firewall... Most (92%) are port 137 windows crap.. Anyone else with data? - jim _______________________________________________ RLUG mailing list [EMAIL PROTECTED] http://www.rlug.org/mailman/listinfo/rlug _______________________________________________ RLUG mailing list [EMAIL PROTECTED] http://www.rlug.org/mailman/listinfo/rlug
