Solved

Router Log - LAN access from remote

Posted on 2009-04-04
7
1,040 Views
Last Modified: 2012-08-13
My Router log gives me the following informaion:

-------------------------------
[LAN access from remote] from 198.175.112.105:41587 to XXX.XXX.XXX:25, Friday, April 03,2009 23:56:08 [LAN access from remote] from 83.240.154.46:19641 to XXX.XXX.XXX:25, Friday, April 03,2009 23:50:05 [LAN access from remote] from 92.80.195.77:1858 to XXX.XXX.XXX:25, Friday, April 03,2009 23:38:54 [LAN access from remote] from 201.236.173.91:13502 to XXX.XXX.XXX:25,
------------------------------

XXX.XXX.XXX is the IP of my SBS2003.

I do not recognize the remote IPs. Should I be worried? Does this mean remote access was attempted or succeeded?

If so, what can I do to stop it?
0
Comment
Question by:hgj1357
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
  • 2
  • +1
7 Comments
 
LVL 4

Assisted Solution

by:blissbear
blissbear earned 300 total points
ID: 24068772
Port 25 is used to run SMTP servers. There are many email spammers out on the internet which regularly scan for open SMTP ports with misconfigured SMTP servers through which they can relay their spam email through.

If you have your SBS2003 box set up to receive email messages for a subnet or dns entry this activity is normal behavior.

If you don't receive email through your SBS2003 box, you can stop this activity by either setting up a firewall filter at your router or through disabling your SMTP server on your SBS2003 box.

If you are using a NAT router for your LAN, it's also likely that the SBS2003 is setting up a uPNP port forward for port 25 to itself.
0
 
LVL 2

Author Comment

by:hgj1357
ID: 24068779
SBS is running exchange and accepts email. You're right, port 25.

I'm I correct in thinking that if the SBS is set up correctly I should be ok?
0
 
LVL 4

Assisted Solution

by:blissbear
blissbear earned 300 total points
ID: 24068826
If your SBS is set up correctly and you have the most recent updates from Microsoft, then you should be fine in my opinion. :)
0
Simple, centralized multimedia control

Watch and learn to see how ATEN provided an easy and effective way for three jointly-owned pubs to control the 60 televisions located across their three venues utilizing the ATEN Control System, Modular Matrix Switch and HDBaseT extenders.

 
LVL 10

Expert Comment

by:ampranti
ID: 24072083
Check your mail server if is an open relay. Apply latest patches.
Use a more sophisticated firewall (doing smtp inspection) and you are fine
0
 
LVL 7

Expert Comment

by:Maeros
ID: 24080320
A surefire way to check to see if your SMTP is restricted properly would be to run a quick SMTP test externally.

Try going to the following link and enter your mail server's address.  If your SMTP has been set up correctly, all parts of the test should pass.  The results shouldn't be too difficult to interpret, however to be sure please post the test results.
0
 
LVL 7

Accepted Solution

by:
Maeros earned 200 total points
ID: 24080328
Well I suppose it would help if I actually posted the link.  My goof ;)

http://www.mxtoolbox.com/diagnostic.aspx
0
 
LVL 2

Author Closing Comment

by:hgj1357
ID: 31566627
I was concerned with the router logs than the mail server but the responses were useful
0

Featured Post

Building an interactive eFuture classroom

Watch and learn how ATEN provided a total control system solution including seamless switching matrix switch, HDBaseT extenders, PDU, lighting control to build an interactive eFuture classroom.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

If you’re like me and you like peace and quiet, saving money, and pretty lights, then this article is for you. For financial reasons, I buy all the Cisco equipment for my home lab second-hand. The first thing to wear out is usually one of the coo…
Arrow Electronics was searching for a KVM  (Keyboard/Video/Mouse) switch that could display on one single monitor the current status of all units being tested on the rack.
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question