Hi all, The last 3 weeks our firewall gets hit by these packets : input DENY eth1 PROTO=6 xxx.xxx.xxx.xxx:xxx 255.255.255.255:1124 L=40 S=0x00 I=51672 F=0x0000 T=238 comming from different source address ( maybe spoofed) and from various reserved ports (ftp,telnet,irc,...). But they are trying to hit a service on port 1124 (in broadcast mode). Does anybody know what service normaly runs on port 1124 ? thanks, wim [EMAIL PROTECTED] - [To unsubscribe, send mail to [EMAIL PROTECTED] with "unsubscribe firewalls" in the body of the message.]
