Firewall is getting contantly hit from a range of IP's, what can I do?

trmiv

Lifer
Oct 10, 1999
14,670
18
81
Every day I get an email log from my firewall, and every day its the same thing.

Mon, 12/08/2003 15:34:37 - TCP connection dropped - Source:69.17.176.156, 4518, WAN - Destination:XXX.XXX.XXX.XXX, 135, LAN - 'Suspicious TCP Data'"

The first two octets of the IP are always 69.17, but the last two are usually different. The ports are always high numbers between 1200 and 4600. It always tries the same thing, port 135 (the RPC port, which was exploited by the Blaster worm). A WHOIS on these IP's show they are all from Aurora Cable Internet.

Is there something I can do about this? Nothing is getting through because of the firewall, but it's getting annoying having the logs filled up with this.
 

Thoreau

Golden Member
Jan 11, 2003
1,441
0
76
Short of complaining to that ISP with log evidence, just instruct your firewall manually to drop packets from that range.
 

Matthias99

Diamond Member
Oct 7, 2003
8,808
0
0
It's just people with Blaster on their machines looking for someone to infect. They probably don't even know they've got it! This is why you don't run unprotected machines on a live Internet connection.

Your firewall is properly blocking it, so there's not much else to do. Can you tell the log to ignore those events? You didn't mention what kind of firewall it is...
 

gunrunnerjohn

Golden Member
Nov 2, 2002
1,360
0
0
Be glad that the firewall is doing it's job.
rolleye.gif
 

JackMDS

Elite Member
Super Moderator
Oct 25, 1999
29,522
410
126
Originally posted by: trmiv
Every day I get an email log from my firewall, and every day its the same thing
LOL, a Person of Interest.:eek:

Welcome to the ?Big League? of Broadband Internet. :beer:

BTW, do not forget to switch off the firewall's email option. :brokenheart:
rolleye.gif
 

trmiv

Lifer
Oct 10, 1999
14,670
18
81
The firewall is Netgear FVS318, I get the logs emailed beacuse it also emails which IP's are passed through the to the web server too, which my boss wants to see in addition to the web server logs.

This firewall is being replaced soon by a Zywall 30w, which I think does have the option to ignore certain messages, so I could set it up to do that. They will likely increase with that firewall though, because it supports multi-nat, and I will have 8 public IP's setup with that thing.