Could this be a long time-base scan?
Could this be a reflection from a DoS against that host?

Jul  4 15:06:18: denied tcp 200.223.1.120(44674) -> x.x.x.112(43839), 1
packet
Jul  5 21:27:36: denied tcp 200.223.1.120(26610) -> x.x.x.101(46412), 1
packet
Jul  6 11:36:02: denied tcp 200.223.1.120(51844) -> y.y.y.2(57785), 1 packet
Jul  6 19:08:27: denied tcp 200.223.1.120(65129) -> x.x.x.109(59390), 1
packet

(two of the destination hosts are non-existent)



-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]

Reply via email to