Seeing port scans on a LAN device when no NAT/etc is set up.
Options
USG110
Default(ish) setup, with a Netgear Orbi sitting on lan1 port. The Orbi keeps showing these log lines:
The only non-default config is the definition of a host object, and a policy allowing:
host -> zywal (IP:any/any) for HTTPS to allow remote management of USG from one specific location.
Will welcome any ideas as to how the ORbi gets scanned while sitting behind a firewall.
Default(ish) setup, with a Netgear Orbi sitting on lan1 port. The Orbi keeps showing these log lines:
[DoS Attack: ACK Scan] from source: 17.248.147.83, port 443, Wednesday, May 13, 2020 10:56:59 [DoS Attack: ACK Scan] from source: 17.248.147.108, port 443, Wednesday, May 13, 2020 10:50:08 [DoS Attack: ACK Scan] from source: 74.125.206.128, port 443, Wednesday, May 13, 2020 10:50:04 [DoS Attack: ACK Scan] from source: 17.248.147.45, port 443, Wednesday, May 13, 2020 10:49:29But no NAT or similar rule has been set up.
The only non-default config is the definition of a host object, and a policy allowing:
host -> zywal (IP:any/any) for HTTPS to allow remote management of USG from one specific location.
Will welcome any ideas as to how the ORbi gets scanned while sitting behind a firewall.
0
Accepted Solution
All Replies
Categories
- All Categories
- 434 Beta Program
- 2.7K Nebula
- 174 Nebula Ideas
- 117 Nebula Status and Incidents
- 6.1K Security
- 418 USG FLEX H Series
- 297 Security Ideas
- 1.6K Switch
- 78 Switch Ideas
- 1.2K Wireless
- 43 Wireless Ideas
- 6.7K Consumer Product
- 269 Service & License
- 416 News and Release
- 87 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.1K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 84 About Community
- 87 Security Highlight