Jump to content

Recommended Posts

Posted

Currently being hammered by IP 93.184.221.240 which according to AbuseIPDB is know for port scanning.

 

I have switched the outgoing IP address on our smoothwall box and within seconds this IP picks up the new IP address and carries on.

 

I'm wondering if this is just a port scan or do I have an infected device on my network.

 

If is possible to see which internal IP this address is trying to reach via some cmd line wizardry as the live firewall report only shows that ip hitting the our External IP.

 

Just wondered if this is possible before I try calling Smoothwall.

 

Cheers

Posted (edited)

No - the traffic is going to the external IP - there will be no internal system IP in any packet that can be seen.

 

What you could do is enable IDS on your LAN/BYOD interfaces and enable the Current Events, Known Malicious Sources, Malware, Virus policies. That will show in the IDS logs if any outgoing traffic matches these policies.

Edited by ibpalle

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...