Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

lots of netbios (137) port logs 1

Status
Not open for further replies.

cpeloso

IS-IT--Management
Nov 29, 2002
25
IT
Hi,
it's about 2 month that my pix 515 logs a lot (about 400 a day) of port 137 udp connection requests from all over the world..
It's a kind of attack?
Or what?
ThankYou
 
It probably is. People try to open shares that are open even from the internet....some windows (l)users have their whole hdd open. You should filter all incoming connections on port 137 to 139 tcp/udp.
 
FYI
There are lots of netbios broadcasts that are advertisements targeting all the cable and DSL users who do not have a firewall It is the same a typing >net send in cmd if you have a system that is on the internet via DSL or Cable with out filtering you will see these messages that are from lose weight to bad sites and they look like a system message

Brock D. Mowry
Hardware Specialist
 
Do you place an implicit deny rule on the PIX to keep these from coming across or is all unstated traffic from inbound connection already blocked?
 
Unless you specifically opened port 137 for any of your IPs, it's being blocked by default. That's the beauty of a firewall -- everything is blocked unless you specify otherwise.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top