A coworker feels that we are being targetted by port scans, ip flooding, and ip spoofing. Does the attached information from the log file support that view?
Time Priority Category Message Source Destination Notes Rule
10:08:59 AM Notice Network Access UDP packet dropped 202.57.149.114, 1458, WAN 239.255.255.250, 137 UDP NetBios NS UDP
10:28:49 AM Notice Network Access UDP packet dropped 87.203.219.210, 17943, WAN 202.57.149.114, 57850, WAN UDP Port: 57850
37:30.3 Alert Intrusion Prevention Possible port scan dropped 209.85.201.83, 80, OPT, wf-in-f83.google.com 192.168.0.2, 34580, OPT TCP scanned port list, 34576, 34573, 34575, 34577, 34579
10:40:53 AM Notice Network Access TCP connection dropped 216.118.117.201, 3773, WAN 202.57.149.114, 16889, WAN TCP Port: 16889
10:43:53 AM Notice Network Access TCP connection dropped 202.57.1.138, 3597, WAN 202.57.149.114, 135, WAN TCP DCE EndPoint
10:46:34 AM Notice Network Access UDP packet dropped 58.137.64.34, 137, WAN 202.57.149.114, 137, WAN UDP NetBios NS UDP
10:50:04 AM Notice Network Access UDP packet dropped 60.222.224.131, 35741, WAN 202.57.149.114, 1026, WAN UDP Port: 1026
00:05.7 Alert Intrusion Prevention Possible port scan dropped 203.149.62.175, 80, WAN 202.57.149.114, 40204, WAN TCP scanned port list, 40176, 40176, 40176, 40176, 40176
11:41:02 AM Notice Network Access UDP packet dropped 202.155.201.226, 35687, WAN 202.57.149.114, 137, WAN UDP NetBios NS UDP
11:41:42 AM Notice Network Access Web management request allowed 151.33.210.78, 49992, WAN 202.57.149.114, 80, WAN TCP HTTP
11:44:00 AM Notice Network Access UDP packet dropped 60.222.224.130, 46194, WAN 202.57.149.115, 1026, WAN UDP Port: 1026
11:49:13 AM Notice Network Access UDP packet dropped 58.137.64.34, 137, WAN 202.57.149.114, 137, WAN UDP NetBios NS UDP
11:53:49 AM Notice Network Access UDP packet dropped 60.222.224.135, 49385, WAN 202.57.149.115, 1026, WAN UDP Port: 1026
57:46.4 Alert Intrusion Prevention Possible port scan dropped 209.85.201.18, 80, OPT, wf-in-f18.google.com 192.168.0.2, 46504, OPT TCP scanned port list, 46497, 46502, 46498, 46500, 46501
12:01:22 PM Notice Network Access UDP packet dropped 60.222.224.134, 34100, WAN 202.57.149.114, 1026, WAN UDP Port: 1026
32:01.7 Alert Intrusion Prevention Possible port scan dropped 209.85.201.83, 80, OPT, wf-in-f83.google.com 192.168.0.2, 53464, OPT TCP scanned port list, 51696, 51699, 51700, 51701, 51703
12:33:24 PM Notice Network Access UDP packet dropped 220.104.6.73, 10851, WAN 202.57.149.114, 53524, WAN UDP Port: 53524
12:36:13 PM Notice Network Access UDP packet dropped 61.23.235.214, 0, WAN 202.57.149.114 UDP Port: 0
12:51:08 PM Notice Network Access UDP packet dropped 58.137.64.34, 137, WAN 202.57.149.114, 137, WAN UDP NetBios NS UDP
1:12:21 PM Notice Network Access UDP packet dropped 60.222.224.136, 48509, WAN 202.57.149.114, 1026, WAN UDP Port: 1026
1:19:02 PM Notice Network Access Web management request allowed 74.208.148.159, 50052, WAN 202.57.149.114, 80, WAN TCP HTTP
1:21:46 PM Notice Network Access UDP packet dropped 60.222.224.133, 59289, WAN 202.57.149.114, 1026, WAN UDP Port: 1026
Start Free Trial