mdrabble Posted February 1, 2024 Posted February 1, 2024 Currently being hammered by IP 93.184.221.240 which according to AbuseIPDB is know for port scanning. I have switched the outgoing IP address on our smoothwall box and within seconds this IP picks up the new IP address and carries on. I'm wondering if this is just a port scan or do I have an infected device on my network. If is possible to see which internal IP this address is trying to reach via some cmd line wizardry as the live firewall report only shows that ip hitting the our External IP. Just wondered if this is possible before I try calling Smoothwall. Cheers
ibpalle Posted February 1, 2024 Posted February 1, 2024 (edited) No - the traffic is going to the external IP - there will be no internal system IP in any packet that can be seen. What you could do is enable IDS on your LAN/BYOD interfaces and enable the Current Events, Known Malicious Sources, Malware, Virus policies. That will show in the IDS logs if any outgoing traffic matches these policies. Edited February 1, 2024 by ibpalle
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now