Router Log - LAN access from remote

My Router log gives me the following informaion:

[LAN access from remote] from to XXX.XXX.XXX:25, Friday, April 03,2009 23:56:08 [LAN access from remote] from to XXX.XXX.XXX:25, Friday, April 03,2009 23:50:05 [LAN access from remote] from to XXX.XXX.XXX:25, Friday, April 03,2009 23:38:54 [LAN access from remote] from to XXX.XXX.XXX:25,

XXX.XXX.XXX is the IP of my SBS2003.

I do not recognize the remote IPs. Should I be worried? Does this mean remote access was attempted or succeeded?

If so, what can I do to stop it?
Who is Participating?
MaerosConnect With a Mentor Commented:
Well I suppose it would help if I actually posted the link.  My goof ;)
blissbearConnect With a Mentor Commented:
Port 25 is used to run SMTP servers. There are many email spammers out on the internet which regularly scan for open SMTP ports with misconfigured SMTP servers through which they can relay their spam email through.

If you have your SBS2003 box set up to receive email messages for a subnet or dns entry this activity is normal behavior.

If you don't receive email through your SBS2003 box, you can stop this activity by either setting up a firewall filter at your router or through disabling your SMTP server on your SBS2003 box.

If you are using a NAT router for your LAN, it's also likely that the SBS2003 is setting up a uPNP port forward for port 25 to itself.
hgj1357Author Commented:
SBS is running exchange and accepts email. You're right, port 25.

I'm I correct in thinking that if the SBS is set up correctly I should be ok?
We Need Your Input!

WatchGuard is currently running a beta program for our new macOS Host Sensor for our Threat Detection and Response service. We're looking for more macOS users to help provide insight and feedback to help us make the product even better. Please sign up for our beta program today!

blissbearConnect With a Mentor Commented:
If your SBS is set up correctly and you have the most recent updates from Microsoft, then you should be fine in my opinion. :)
Check your mail server if is an open relay. Apply latest patches.
Use a more sophisticated firewall (doing smtp inspection) and you are fine
A surefire way to check to see if your SMTP is restricted properly would be to run a quick SMTP test externally.

Try going to the following link and enter your mail server's address.  If your SMTP has been set up correctly, all parts of the test should pass.  The results shouldn't be too difficult to interpret, however to be sure please post the test results.
hgj1357Author Commented:
I was concerned with the router logs than the mail server but the responses were useful
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.