I notice in my logs that I have connections coming from the internet to the 
external interface of our firewall.  The source is from a 10.xxx.xxx.xxx 
networks (non routable), and of course could not traverse the internet on 
its way back.  I was wondering if anyone else sees this, and what they may 
be trying to do.  They are using high port #.  It is all getting dropped, 
but I still wonder what is happening.

On a different note, we also see from time to time, machines in our DMZ 
trying to make connections out to the internet using HTTP and HTTPS.  The 
address' they are trying to connect to gives "destination host unreachable" 
when we try to ping them.  I have talked to the admins on those machines, 
and they are saying that nothing they are doing should make http connections 
to the internet.

any ideas ?
_________________________________________________________________
Get your FREE download of MSN Explorer at http://explorer.msn.com



================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to