Ok.  Like our Cisco?

-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On
Behalf Of John Tolmachoff (Lists)
Sent: Monday, June 02, 2003 1:48 PM
To: [EMAIL PROTECTED]
Subject: RE: [SonicWALL]- TCP FIN Scans?


That is why you are still seeing it. You only blocked it in a access
rule. You need to block it at the router.

John Tolmachoff MCSE CSSA
Engineer/Consultant
eServices For You
www.eservicesforyou.com


> -----Original Message-----
> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On 
> Behalf Of [EMAIL PROTECTED]
> Sent: Monday, June 02, 2003 11:30 AM
> To: [EMAIL PROTECTED]
> Subject: RE: [SonicWALL]- TCP FIN Scans?
> 
> I've blocked the range in the access list(Denied LAN to ip, default is

> deny IP to LAN as well) and put the IP in the content filter blocking.

> Still no go.
> 
> -----Original Message-----
> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On 
> Behalf Of Limmer, Jim
> Sent: Monday, June 02, 2003 1:13 PM
> To: [EMAIL PROTECTED]
> Subject: RE: [SonicWALL]- TCP FIN Scans?
> 
> 
> 
> You may be blocking it in the content filter by name - which has no 
> effect if the web page is pointing you at it numerically. you may want

> to add that numberic IP to the content filter. Or better yet block the

> whole range at your router level.
> 
> That is of course, if you don't like advertising. :)
> 
> 
> 
> -----Original Message-----
> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]
> Sent: Monday, June 02, 2003 1:50 PM
> To: [EMAIL PROTECTED]
> Subject: RE: [SonicWALL]- TCP FIN Scans?
> 
> 
> That's the weird thing - I am blocking it!!??
> 
> -----Original Message-----
> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On 
> Behalf Of Limmer, Jim
> Sent: Monday, June 02, 2003 12:39 PM
> To: [EMAIL PROTECTED]
> Subject: RE: [SonicWALL]- TCP FIN Scans?
> 
> 
> 
> I get these also. this is ad.doubleclick.net - you'll find them from a

> variety of other websites.
> 
> What happens is you connect to a website which connects you to the ad 
> server - during the time that you are connected there the sonicwall 
> 'times out' your connection, and the ad server tries to continue 
> communicating with you - thus triggering an event.
> 
> Since this particular one is an ad server, you might consider blocking

> it.
> 
> -Jim
> 
> 
> 
> 
> -----Original Message-----
> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]
> Sent: Monday, June 02, 2003 1:26 PM
> To: [EMAIL PROTECTED]
> Subject: [SonicWALL]- TCP FIN Scans?
> 
> 
> Recently I have been receiving multiple TCP FIN scans per day coming 
> from a specific address.  Listed below is an excerpt from our 
> SonicWALL:
> 
> Probable TCP FIN scan -       Source:216.73.82.11, 80
> 
> The destination of course is that of our SonicWALL's public IP 
> address.
> 
> Anyone know how to stop this?  I get about 6-7 emails per day (during 
> business hours only), all identical from the same IP address listed 
> above.  Any help would really be appreciated.  Thanks.
> 
> Marcus D. Gand
> Director of Information Technologies
> LaurenKamtech, Inc.
> [EMAIL PROTECTED]
> 
> 
> 
> NOTICE TO OUR CUSTOMERS:
> All laurenec.com email addresses have now changed format to
> 
> [EMAIL PROTECTED]  While the old format may still
> 
> work, it is recommended that you update your address books to the new
> 
> format.  Thank you. - LaurenKamtech I.T. Department
> 
> 
> ---
> [This E-mail scanned for viruses by Declude/F-Prot AV]
> 
> =================================
> To unsubscribe, send email to [EMAIL PROTECTED] In the body of the 
> email put the following: unsubscribe sonicwall your_name The archive 
> of this list is at http://www.mail-archive.com/sonicwall%40peake.com/
> 
> 
> 
> 
> LEGAL NOTICE:
> Unless expressly stated otherwise, this message is confidential and 
> may be privileged. It is intended for the addressee(s) only. Access to

> this e-mail by anyone else is unauthorized. If you are not an 
> addressee, any disclosure or copying of the contents or any action 
> taken (or not taken) in reliance on it is unauthorized and may be 
> unlawful. If you are not an addressee, please inform the sender 
> immediately.
> ---
> [This E-mail scanned for viruses by Declude/F-Prot AV]
> 
> =================================
> To unsubscribe, send email to [EMAIL PROTECTED] In the body of the 
> email put the following: unsubscribe sonicwall your_name The archive 
> of this list is at http://www.mail-archive.com/sonicwall%40peake.com/
> 
> 
> 
> NOTICE TO OUR CUSTOMERS:
> All laurenec.com email addresses have now changed format to
> 
> [EMAIL PROTECTED]  While the old format may still
> 
> work, it is recommended that you update your address books to the new
> 
> format.  Thank you. - LaurenKamtech I.T. Department
> 
> 
> ---
> [This E-mail scanned for viruses by Declude/F-Prot AV]
> 
> =================================
> To unsubscribe, send email to [EMAIL PROTECTED] In the body of the 
> email put the following: unsubscribe sonicwall your_name The archive 
> of this list is at http://www.mail-archive.com/sonicwall%40peake.com/
> 
> 
> 
> 
> LEGAL NOTICE:
> Unless expressly stated otherwise, this message is confidential and 
> may be privileged. It is intended for the addressee(s) only. Access to

> this e-mail by anyone else is unauthorized. If you are not an 
> addressee, any disclosure or copying of the contents or any action 
> taken (or not taken) in reliance on it is unauthorized and may be 
> unlawful. If you are not an addressee, please inform the sender 
> immediately.
> ---
> [This E-mail scanned for viruses by Declude/F-Prot AV]
> 
> =================================
> To unsubscribe, send email to [EMAIL PROTECTED] In the body of the 
> email put the following: unsubscribe sonicwall your_name The archive 
> of this list is at http://www.mail-archive.com/sonicwall%40peake.com/
> 
> 
> 
> NOTICE TO OUR CUSTOMERS:
> All laurenec.com email addresses have now changed format to
> 
> [EMAIL PROTECTED]  While the old format may still
> 
> work, it is recommended that you update your address books to the new
> 
> format.  Thank you. - LaurenKamtech I.T. Department
> 
> 
> ---
> [This E-mail scanned for viruses by Declude/F-Prot AV]
> 
> =================================
> To unsubscribe, send email to [EMAIL PROTECTED] In the body of the 
> email
put
> the following: unsubscribe sonicwall your_name
> The archive of this list is at
http://www.mail-archive.com/sonicwall%40peake.com/
> 


---
[This E-mail scanned for viruses by Declude/F-Prot AV]

=================================
To unsubscribe, send email to [EMAIL PROTECTED] In the body of the
email put the following: unsubscribe sonicwall your_name The archive of
this list is at http://www.mail-archive.com/sonicwall%40peake.com/



NOTICE TO OUR CUSTOMERS:
All laurenec.com email addresses have now changed format to 
[EMAIL PROTECTED]  While the old format may still 
work, it is recommended that you update your address books to the new 
format.  Thank you. – LaurenKamtech I.T. Department


---
[This E-mail scanned for viruses by Declude/F-Prot AV]

==================================================================================================To
 unsubscribe, send email to [EMAIL PROTECTED] In the body of the email put the 
following: unsubscribe sonicwall your_name
The archive of this list is at http://www.mail-archive.com/sonicwall%40peake.com/


Reply via email to