We help IT Professionals succeed at work.
Get Started

I'm sending through my Linux Proxy / Gateway port scans to public ips

ltpitt
ltpitt asked
on
405 Views
Last Modified: 2014-03-18
I got an email with this content:

>MYSERVERIP was observed probing AGUYWEBSITE for security holes. It
>has been blocked at our border routers. It may be compromised.
>
>For more info contact THEGUY
>Please include the entire subject line of the original message
>
>     THEGUY
>
>(time zone of log is PST, which is UTC-08:00, date is MMDD)
>log entries are from Cisco netflow, time is flow start time
>date.time         srcIP          srcPort dstIP          dstPort proto
>#pkts
>0225.13:47:49.302 MYSERVERIP   3876 HISSERVERIP        445    6
>2
>0225.14:03:35.086 MYSERVERIP   2875 HISSERVERIP      445    6
>2

-SNIP-

My LAN connects to the internet using a Debian Firewall / Gateway / Proxy.

How can I track down where's the problem?
Comment
Watch Question
CERTIFIED EXPERT
Top Expert 2014
Commented:
This problem has been solved!
Unlock 1 Answer and 11 Comments.
See Answer
Why Experts Exchange?

Experts Exchange always has the answer, or at the least points me in the correct direction! It is like having another employee that is extremely experienced.

Jim Murphy
Programmer at Smart IT Solutions

When asked, what has been your best career decision?

Deciding to stick with EE.

Mohamed Asif
Technical Department Head

Being involved with EE helped me to grow personally and professionally.

Carl Webster
CTP, Sr Infrastructure Consultant
Ask ANY Question

Connect with Certified Experts to gain insight and support on specific technology challenges including:

  • Troubleshooting
  • Research
  • Professional Opinions
Did You Know?

We've partnered with two important charities to provide clean water and computer science education to those who need it most. READ MORE