Seeing port scans on a LAN device when no NAT/etc is set up.
Options
USG110
Default(ish) setup, with a Netgear Orbi sitting on lan1 port. The Orbi keeps showing these log lines:
The only non-default config is the definition of a host object, and a policy allowing:
host -> zywal (IP:any/any) for HTTPS to allow remote management of USG from one specific location.
Will welcome any ideas as to how the ORbi gets scanned while sitting behind a firewall.
Default(ish) setup, with a Netgear Orbi sitting on lan1 port. The Orbi keeps showing these log lines:
[DoS Attack: ACK Scan] from source: 17.248.147.83, port 443, Wednesday, May 13, 2020 10:56:59 [DoS Attack: ACK Scan] from source: 17.248.147.108, port 443, Wednesday, May 13, 2020 10:50:08 [DoS Attack: ACK Scan] from source: 74.125.206.128, port 443, Wednesday, May 13, 2020 10:50:04 [DoS Attack: ACK Scan] from source: 17.248.147.45, port 443, Wednesday, May 13, 2020 10:49:29But no NAT or similar rule has been set up.
The only non-default config is the definition of a host object, and a policy allowing:
host -> zywal (IP:any/any) for HTTPS to allow remote management of USG from one specific location.
Will welcome any ideas as to how the ORbi gets scanned while sitting behind a firewall.
0
Accepted Solution
All Replies
Categories
- All Categories
- 442 Beta Program
- 3K Nebula
- 228 Nebula Ideas
- 130 Nebula Status and Incidents
- 6.6K Security
- 648 USG FLEX H Series
- 357 Security Ideas
- 1.8K Switch
- 86 Switch Ideas
- 1.4K Wireless
- 55 Wireless Ideas
- 7.1K Consumer Product
- 304 Service & License
- 496 News and Release
- 94 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5K FAQ
- 34 Documents
- 89 About Community
- 110 Security Highlight
Freshman Member
Master Member