[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [FW1] Interesting HTTP connects in logs.
I am getting a TON of http connections to my firewall (droped). they are all from netscape.com They are TCP connections with the S_PORT being 80. The Firewall is acting as a NAT for the internal network. I am getting about 20 a minute and it's getting annoying. Is it possible that netscape.com has resorted to some sort of SpyWare or something like that? It's odd that the web server would attempt to connect back to the person here after the fact. The IP's are 207.200.75.9 / 207.200.75.10 / 207.200.75.48 I have also noticed that geocities does this as well.. 209.1.224.15.. Should I just add a rule to drop all http requests to the firewall and not log them? (currently my stealth rule creates an alert on any connection attempt to the firewall itself...) Joe ====================================================================== Joseph Voisin, Systems Administrator, Engel Canada Inc. www.engelmachinery.com | [email protected] |PGP Fingerprint: A20B 135D 0920 074F C7FE D72D 88A7 2521 5138 DFC2 ====================================================================== ================================================================================ To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================================================
|