Seeing port scans on a LAN device when no NAT/etc is set up.
USG110
Default(ish) setup, with a Netgear Orbi sitting on lan1 port. The Orbi keeps showing these log lines:
The only non-default config is the definition of a host object, and a policy allowing:
host -> zywal (IP:any/any) for HTTPS to allow remote management of USG from one specific location.
Will welcome any ideas as to how the ORbi gets scanned while sitting behind a firewall.
Default(ish) setup, with a Netgear Orbi sitting on lan1 port. The Orbi keeps showing these log lines:
[DoS Attack: ACK Scan] from source: 17.248.147.83, port 443, Wednesday, May 13, 2020 10:56:59 [DoS Attack: ACK Scan] from source: 17.248.147.108, port 443, Wednesday, May 13, 2020 10:50:08 [DoS Attack: ACK Scan] from source: 74.125.206.128, port 443, Wednesday, May 13, 2020 10:50:04 [DoS Attack: ACK Scan] from source: 17.248.147.45, port 443, Wednesday, May 13, 2020 10:49:29But no NAT or similar rule has been set up.
The only non-default config is the definition of a host object, and a policy allowing:
host -> zywal (IP:any/any) for HTTPS to allow remote management of USG from one specific location.
Will welcome any ideas as to how the ORbi gets scanned while sitting behind a firewall.
0
Accepted Solution
All Replies
Categories
- All Categories
- 415 Beta Program
- 2.3K Nebula
- 141 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 218 USG FLEX H Series
- 262 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1K Wireless
- 39 Wireless Ideas
- 6.3K Consumer Product
- 245 Service & License
- 382 News and Release
- 81 Security Advisories
- 27 Education Center
- 8 [Campaign] Zyxel Network Detective
- 3.1K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight