Contributor
tower12
Posts: 23
Registered: ‎04-27-2012
router Firewall warnings

Hi,

last two days Ive been getting warnings when checking my routers ( Bt Home Hub 2 wireless) firewall history event history -security. Under advice I turned off UpnP yesterday afternoon. Jsut checked again And get the follwoing messages:

 

The 81.xxx adress corresponds to my  Network Ip adrress The 192xxx .66 realtes to a family members Ipod. What is going on here & what is The Ipod trying to do  - no one was anyhwere nearer it at this time of the morning.

 

Very grateful if

1)anyone could explain what these messages mean &

2)perhaps  help me understand what thsi Ipod is trying to do - without anyone using it?.

3)Also, should 360 be picking up these attempts at connection at all - I cant see any such warnings in Norton?. Appreciate anyones help.

 

:38:06  28 AprFIREWALL icmp check (1 of 1): Protocol: ICMP Src ip: 184.173.146.3 Dst ip: 81.xxxxxxx Type: Destination Unreachable Code: Port Unreacheable
08:48:12  28 AprIDS scan parser : udp port scan: 213.172.34.234 scanned at least 20 ports at 81.xxxxxxxxx. (1 of 1) : 213.172.34.234 81.158.210.129 0056 UDP 61483->50430
08:09:24  28 AprFIREWALL icmp check (1 of 1): Protocol: ICMP Src ip: 119.199.114.60 Dst ip:81. xxxxxxxType: Destination Unreachable Code: Host Unreacheable
06:03:28  28 AprIDS proto parser : tcp invalid urgent offset (1 of 15) : 192.xx.66 126.233.94.94 0052 TCP 53766->443 [.FA.U.] seq 3918315724 ack 248545603 win 16383
06:00:22  28 AprIDS proto parser : tcp invalid urgent offset (1 of 1) : 192.xx.66 126.233.94.94 0052 TCP 53766->443 [.FA.U.] seq 3918315724 ack 248545602 win 16383
SendOfJive
Posts: 9,971
Kudos: 4,216
Solutions: 708
Registered: ‎02-07-2009
Re: router Firewall warnings
[ Edited ]

Hi tower12,

 

These look like normal events in the life of a router.  If you are connected to the internet you are going to get unsolicited connection attempts, which the router will block.  Any incoming communication which is not a response to a request sent out by a device on your LAN is going to be blocked as a portscan.  The first three entries appear to be portscans that are probably just internet background noise. Norton will never see any of these because the router is preventing them from reaching your computer, as it should.  You can't do anything about such connection attempts any more than you can prevent anyone from dialing your phone number.  All you can do is refuse to answer, which is what your router is doing.

 

The traffic in the entries you identify as involving the iPod has characteristics that the router's firewall intrusion detection system regards as suspicious,  I am not too familiar with iPods or this router, but it looks like the iPod is attempting to connect out to a remote address - have you checked with Apple about what sorts of connections the iPod carries out routinely. (it's not like there aren't a lot of apps that would be phoning home or casting about for who-knows-what)? 

Contributor
tower12
Posts: 23
Registered: ‎04-27-2012
Re: router Firewall warnings

Thanks for the reply,very helpful.

What do you think the Ipod is trying to do?. Why would it try to connect to a remote address?

Puzzling.

DistEd2
Posts: 1,515
Kudos: 315
Solutions: 68
Registered: ‎08-11-2011
Re: router Firewall warnings

I'm an Android person myself, but I would imagine iPhone apps work the same way: smartphone apps "call home" all the time, to check for updates or to synchronize your data or to pull down announcements, etc. That's likely what you're seeing.

Contributor
tower12
Posts: 23
Registered: ‎04-27-2012
Re: router Firewall warnings

Thanks. Quick point. My Wireless Router disables Wireless signal overnight ,I also dissconnect the ethernet cable (from my wired machine) at night. So, how can these attacks still be happening?.  Is it beacuse the router reamins on & powered up with a broadband connection.?.

SendOfJive
Posts: 9,971
Kudos: 4,216
Solutions: 708
Registered: ‎02-07-2009
Re: router Firewall warnings

Yes.

DistEd2
Posts: 1,515
Kudos: 315
Solutions: 68
Registered: ‎08-11-2011
Re: router Firewall warnings

Yes, exactly (referring to the port scans). Your original post mentioned that these were being logged on your router, rather than by Norton. So what that means is that your router is sitting there, as a live device at the end of your incoming broadband connection. So anything that's pinging for live devices at it's IP address is going to get a response. But since you have any connections on your side of that router either physically or electronically disabled overnight, nothing except your router is being exposed.