router Firewall warnings
04-28-2012 08:08 AM
Hi,
last two days Ive been getting warnings when checking my routers ( Bt Home Hub 2 wireless) firewall history event history -security. Under advice I turned off UpnP yesterday afternoon. Jsut checked again And get the follwoing messages:
The 81.xxx adress corresponds to my Network Ip adrress The 192xxx .66 realtes to a family members Ipod. What is going on here & what is The Ipod trying to do - no one was anyhwere nearer it at this time of the morning.
Very grateful if
1)anyone could explain what these messages mean &
2)perhaps help me understand what thsi Ipod is trying to do - without anyone using it?.
3)Also, should 360 be picking up these attempts at connection at all - I cant see any such warnings in Norton?. Appreciate anyones help.
| :38:06 28 Apr | FIREWALL icmp check (1 of 1): Protocol: ICMP Src ip: 184.173.146.3 Dst ip: 81.xxxxxxx Type: Destination Unreachable Code: Port Unreacheable |
| 08:48:12 28 Apr | IDS scan parser : udp port scan: 213.172.34.234 scanned at least 20 ports at 81.xxxxxxxxx. (1 of 1) : 213.172.34.234 81.158.210.129 0056 UDP 61483->50430 |
| 08:09:24 28 Apr | FIREWALL icmp check (1 of 1): Protocol: ICMP Src ip: 119.199.114.60 Dst ip:81. xxxxxxxType: Destination Unreachable Code: Host Unreacheable |
| 06:03:28 28 Apr | IDS proto parser : tcp invalid urgent offset (1 of 15) : 192.xx.66 126.233.94.94 0052 TCP 53766->443 [.FA.U.] seq 3918315724 ack 248545603 win 16383 |
| 06:00:22 28 Apr | IDS proto parser : tcp invalid urgent offset (1 of 1) : 192.xx.66 126.233.94.94 0052 TCP 53766->443 [.FA.U.] seq 3918315724 ack 248545602 win 16383 |
Re: router Firewall warnings
[ Edited ]04-28-2012 06:18 PM - edited 04-28-2012 07:00 PM
Hi tower12,
These look like normal events in the life of a router. If you are connected to the internet you are going to get unsolicited connection attempts, which the router will block. Any incoming communication which is not a response to a request sent out by a device on your LAN is going to be blocked as a portscan. The first three entries appear to be portscans that are probably just internet background noise. Norton will never see any of these because the router is preventing them from reaching your computer, as it should. You can't do anything about such connection attempts any more than you can prevent anyone from dialing your phone number. All you can do is refuse to answer, which is what your router is doing.
The traffic in the entries you identify as involving the iPod has characteristics that the router's firewall intrusion detection system regards as suspicious, I am not too familiar with iPods or this router, but it looks like the iPod is attempting to connect out to a remote address - have you checked with Apple about what sorts of connections the iPod carries out routinely. (it's not like there aren't a lot of apps that would be phoning home or casting about for who-knows-what)?
Re: router Firewall warnings
04-29-2012 07:37 AM
I'm an Android person myself, but I would imagine iPhone apps work the same way: smartphone apps "call home" all the time, to check for updates or to synchronize your data or to pull down announcements, etc. That's likely what you're seeing.
Re: router Firewall warnings
04-29-2012 11:14 AM
Thanks. Quick point. My Wireless Router disables Wireless signal overnight ,I also dissconnect the ethernet cable (from my wired machine) at night. So, how can these attacks still be happening?. Is it beacuse the router reamins on & powered up with a broadband connection.?.
Re: router Firewall warnings
04-29-2012 11:35 AM
Yes, exactly (referring to the port scans). Your original post mentioned that these were being logged on your router, rather than by Norton. So what that means is that your router is sitting there, as a live device at the end of your incoming broadband connection. So anything that's pinging for live devices at it's IP address is going to get a response. But since you have any connections on your side of that router either physically or electronically disabled overnight, nothing except your router is being exposed.
