[Hampshire] Port scans

Top Page

Reply to this message
Author: Rob Malpass
Date:  
To: hampshire
Subject: [Hampshire] Port scans
Hi all

I need a bit of networking advice. Recently my network (or rather connection to the internet) has "stalled". By this I mean I'm using firefox (admittedly on Vista) and I've noticed that say I'm heading to wikipedia - it just times out. If I open another tab sometimes this fixes it but on occasion I have had to soft reboot the router.

On each occasion I've noticed entries in the router log saying:
**TCP FIN Scan** or
**SYN Flood to Host**

with:
* my local IP address
* then different ports in the range 62000 to 65000
* then IP addresses that look reasonable / harmless enough like my mail server, my ISP's DNS or Google
* then port 80 (or sometimes 53) then "ATM1 outbound"

First question: Is someone just running a port scan? Sounds unlikely as it's outbound.
Second question: If they are - there's nothing I can do about it is there?

Have I missed anything? One reason I ask is that I'm due for some sort of ADSL line upgrade (to the "21st century network") apparently this week so was wondering if around the time of changeover things might have become a little flaky.

Cheers
Rob