Hi all,

The last 3 weeks our firewall gets hit by these packets :

input DENY eth1 PROTO=6 xxx.xxx.xxx.xxx:xxx 255.255.255.255:1124 L=40 S=0x00
I=51672 F=0x0000 T=238

comming from different source address ( maybe spoofed) and from various
reserved ports (ftp,telnet,irc,...).

But they are trying to hit a service on port 1124 (in broadcast mode).
Does anybody know what service normaly runs on port 1124 ?


thanks,

wim

[EMAIL PROTECTED]



-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]

Reply via email to