Could this be a long time-base scan?
Could this be a reflection from a DoS against that host?
Jul 4 15:06:18: denied tcp 200.223.1.120(44674) -> x.x.x.112(43839), 1
packet
Jul 5 21:27:36: denied tcp 200.223.1.120(26610) -> x.x.x.101(46412), 1
packet
Jul 6 11:36:02: denied tcp 200.223.1.120(51844) -> y.y.y.2(57785), 1 packet
Jul 6 19:08:27: denied tcp 200.223.1.120(65129) -> x.x.x.109(59390), 1
packet
(two of the destination hosts are non-existent)
-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]