Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Router Log - LAN access from remote

Posted on 2009-04-04
7
Medium Priority
?
1,049 Views
Last Modified: 2012-08-13
My Router log gives me the following informaion:

-------------------------------
[LAN access from remote] from 198.175.112.105:41587 to XXX.XXX.XXX:25, Friday, April 03,2009 23:56:08 [LAN access from remote] from 83.240.154.46:19641 to XXX.XXX.XXX:25, Friday, April 03,2009 23:50:05 [LAN access from remote] from 92.80.195.77:1858 to XXX.XXX.XXX:25, Friday, April 03,2009 23:38:54 [LAN access from remote] from 201.236.173.91:13502 to XXX.XXX.XXX:25,
------------------------------

XXX.XXX.XXX is the IP of my SBS2003.

I do not recognize the remote IPs. Should I be worried? Does this mean remote access was attempted or succeeded?

If so, what can I do to stop it?
0
Comment
Question by:hgj1357
  • 2
  • 2
  • 2
  • +1
7 Comments
 
LVL 4

Assisted Solution

by:blissbear
blissbear earned 900 total points
ID: 24068772
Port 25 is used to run SMTP servers. There are many email spammers out on the internet which regularly scan for open SMTP ports with misconfigured SMTP servers through which they can relay their spam email through.

If you have your SBS2003 box set up to receive email messages for a subnet or dns entry this activity is normal behavior.

If you don't receive email through your SBS2003 box, you can stop this activity by either setting up a firewall filter at your router or through disabling your SMTP server on your SBS2003 box.

If you are using a NAT router for your LAN, it's also likely that the SBS2003 is setting up a uPNP port forward for port 25 to itself.
0
 
LVL 2

Author Comment

by:hgj1357
ID: 24068779
SBS is running exchange and accepts email. You're right, port 25.

I'm I correct in thinking that if the SBS is set up correctly I should be ok?
0
 
LVL 4

Assisted Solution

by:blissbear
blissbear earned 900 total points
ID: 24068826
If your SBS is set up correctly and you have the most recent updates from Microsoft, then you should be fine in my opinion. :)
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 
LVL 10

Expert Comment

by:ampranti
ID: 24072083
Check your mail server if is an open relay. Apply latest patches.
Use a more sophisticated firewall (doing smtp inspection) and you are fine
0
 
LVL 7

Expert Comment

by:Maeros
ID: 24080320
A surefire way to check to see if your SMTP is restricted properly would be to run a quick SMTP test externally.

Try going to the following link and enter your mail server's address.  If your SMTP has been set up correctly, all parts of the test should pass.  The results shouldn't be too difficult to interpret, however to be sure please post the test results.
0
 
LVL 7

Accepted Solution

by:
Maeros earned 600 total points
ID: 24080328
Well I suppose it would help if I actually posted the link.  My goof ;)

http://www.mxtoolbox.com/diagnostic.aspx
0
 
LVL 2

Author Closing Comment

by:hgj1357
ID: 31566627
I was concerned with the router logs than the mail server but the responses were useful
0

Featured Post

Get your Conversational Ransomware Defense e‑book

This e-book gives you an insight into the ransomware threat and reviews the fundamentals of top-notch ransomware preparedness and recovery. To help you protect yourself and your organization. The initial infection may be inevitable, so the best protection is to be fully prepared.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article will step through configuring a SonicWALL appliance to utilize an internal DHCP server for Global VPN Client (GVC) hosts.  There are times when using an external (external to the SonicWALL) DHCP server, such as Windows Servers, isn’t pr…
Arrow Electronics was searching for a KVM  (Keyboard/Video/Mouse) switch that could display on one single monitor the current status of all units being tested on the rack.
Integration Management Part 2
How to fix incompatible JVM issue while installing Eclipse While installing Eclipse in windows, got one error like above and unable to proceed with the installation. This video describes how to successfully install Eclipse. How to solve incompa…
Suggested Courses

971 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question