Hi,
My company recently upgraded from a simple Lynksys router to a slightly less simple Netgear Router/Firewall/VPN Appliance.
Works nice, but the device's security logs seems, at least to me, to be taking alot of connection hits.
Can anyone glance over this cut and paste of the logs to tell me if this is an unusual circumstance?
**** Log Edited for Security ****
**** This is only a 5 hour time period ****
Mon, 03/01/2004 00:01:31 - TCP connection dropped - Source:64.7.205.102, 80, WAN - Destination:24.121.xxx.xxx, 1633, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 00:10:05 - TCP connection dropped - Source:172.162.19.74, 3273, WAN - Destination:24.121.xxx.xxx, 80, LAN - 'WEB'
Mon, 03/01/2004 00:11:47 - TCP connection dropped - Source:64.7.205.102, 80, WAN - Destinationestination:24.121.xxx.xxx, 1974, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 00:21:59 - UDP packet dropped - Source:209.98.203.61, 137, WAN - Destination:24.121.xxx.xxx, 137, LAN - 'Suspicious UDP Data'
Mon, 03/01/2004 00:22:17 - TCP connection dropped - Source:220.255.48.56, 2811, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 00:25:01 - TCP connection dropped - Source:24.121.44.182, 4656, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 00:26:55 - TCP connection dropped - Source:200.223.240.122, 4236, WAN - Destination:24.121.xxx.xxx, 1433, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 00:31:45 - UDP packet dropped - Source:24.80.169.130, 1088, WAN - Destination:24.121.xxx.xxx, 137, LAN - 'Suspicious UDP Data'
Mon, 03/01/2004 00:34:31 - TCP connection dropped - Source:64.7.205.102, 80, WAN - Destination:24.121.xxx.xxx, 1717, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 00:39:53 - TCP connection dropped - Source:220.85.119.67, 3287, WAN - Destination:24.121.xxx.xxx, 901, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 00:47:09 - TCP connection dropped - Source:221.197.153.89, 3331, WAN - Destination:24.121.xxx.xxx, 80, LAN - 'WEB'
Mon, 03/01/2004 00:49:25 - TCP connection dropped - Source:222.100.57.163, 2490, WAN - Destination:24.121.xxx.xxx, 901, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 01:01:11 - TCP connection dropped - Source:24.121.46.234, 4047, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 01:02:43 - TCP connection dropped - Source:24.120.206.28, 1252, WAN - Destination:24.121.xxx.xxx, 8866, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 01:10:33 - TCP connection dropped - Source:218.47.19.10, 3526, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 01:30:11 - UDP packet dropped - Source:24.121.40.226, 1025, WAN - Destination:24.121.xxx.xxx, 137, LAN - 'Suspicious UDP Data'
Mon, 03/01/2004 01:33:39 - TCP connection dropped - Source:24.121.61.224, 4722, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 01:51:45 - TCP connection dropped - Source:64.7.205.102, 80, WAN - Destination:24.121.xxx.xxx, 1932, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 01:57:13 - TCP connection dropped - Source:219.162.216.125, 3331, WAN - Destination:24.121.xxx.xxx, 80, LAN - 'WEB'
Mon, 03/01/2004 02:01:35 - TCP connection dropped - Source:211.202.209.234, 4677, WAN - Destination:24.121.xxx.xxx, 901, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 02:28:18 - TCP connection dropped - Source:24.214.100.201, 63715, WAN - Destination:24.121.xxx.xxx, 901, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 02:32:20 - TCP connection dropped - Source:24.121.61.224, 4535, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 02:38:32 - TCP connection dropped - Source:64.7.205.102, 80, WAN - Destination:24.121.xxx.xxx, 1457, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 02:46:48 - UDP packet dropped - Source:65.59.64.107, 7634, WAN - Destination:24.121.xxx.xxx, 1026, LAN - 'Suspicious UDP Data'
Mon, 03/01/2004 02:47:48 - TCP connection dropped - Source:64.7.205.102, 80, WAN - Destination:24.121.xxx.xxx, 1630, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 02:55:34 - UDP packet dropped - Source:24.164.36.33, 8228, WAN - Destination:24.121.xxx.xxx, 12596, LAN - 'Suspicious UDP Data'
Mon, 03/01/2004 02:55:48 - TCP connection dropped - Source:65.105.136.188, 3430, WAN - Destination:24.121.xxx.xxx, 3389, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 03:07:20 - TCP connection dropped - Source:64.7.205.102, 80, WAN - Destination:24.121.xxx.xxx, 1143, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 03:07:38 - TCP connection dropped - Source:193.6.48.64, 1855, WAN - Destination:24.121.xxx.xxx, 3127, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 03:16:02 - TCP connection dropped - Source:200.117.214.80, 61898, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 03:16:40 - TCP connection dropped - Source:24.107.199.171, 220, WAN - Destination:24.121.xxx.xxx, 6129, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 03:28:22 - TCP connection dropped - Source:220.220.145.44, 2628, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 03:35:12 - TCP connection dropped - Source:217.207.184.195, 58565, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 03:35:24 - TCP connection dropped - Source:24.108.76.187, 3148, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 03:44:16 - TCP connection dropped - Source:24.68.215.151, 2196, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 03:44:16 - TCP connection dropped - Source:24.68.215.151, 2198, WAN - Destination:24.121.xxx.xxx, 139, LAN - 'NetBIOS'
Mon, 03/01/2004 03:44:26 - TCP connection dropped - Source:24.68.215.151, 2198, WAN - Destination:24.121.xxx.xxx, 139, LAN - 'Possible Port Scan'
Mon, 03/01/2004 03:45:30 - TCP connection dropped - Source:24.88.180.78, 3129, WAN - Destination:24.121.xxx.xxx, 27374, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 03:55:46 - TCP connection dropped - Source:64.7.205.102, 80, WAN - Destination:24.121.xxx.xxx, 1440, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 03:58:56 - TCP connection dropped - Source:141.158.29.183, 3409, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 04:18:28 - TCP connection dropped - Source:64.7.205.102, 80, WAN - Destination:24.121.xxx.xxx, 1415, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 04:32:50 - TCP connection dropped - Source:80.134.123.62, 2432, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 04:33:34 - TCP connection dropped - Source:195.62.141.6, 2577, WAN - Destination:24.121.xxx.xxx, 3127, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 04:38:04 - TCP connection dropped - Source:64.7.205.102, 80, WAN - Destination:24.121.xxx.xxx, 1929, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 04:40:22 - UDP packet dropped - Source:24.164.33.248, 13796, WAN - Destination:24.121.xxx.xxx, 1026, LAN - 'Suspicious UDP Data'
Mon, 03/01/2004 04:42:08 - TCP connection dropped - Source:212.244.70.21, 1669, WAN - Destination:24.121.xxx.xxx, 21, LAN - 'FTP-ctrl'
Mon, 03/01/2004 04:53:00 - TCP connection dropped - Source:65.65.97.41, 2863, WAN - Destination:24.121.xxx.xxx, 139, LAN - 'NetBIOS'
Mon, 03/01/2004 05:00:28 - TCP connection dropped - Source:24.121.61.166, 1250, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
My company recently upgraded from a simple Lynksys router to a slightly less simple Netgear Router/Firewall/VPN Appliance.
Works nice, but the device's security logs seems, at least to me, to be taking alot of connection hits.
Can anyone glance over this cut and paste of the logs to tell me if this is an unusual circumstance?
**** Log Edited for Security ****
**** This is only a 5 hour time period ****
Mon, 03/01/2004 00:01:31 - TCP connection dropped - Source:64.7.205.102, 80, WAN - Destination:24.121.xxx.xxx, 1633, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 00:10:05 - TCP connection dropped - Source:172.162.19.74, 3273, WAN - Destination:24.121.xxx.xxx, 80, LAN - 'WEB'
Mon, 03/01/2004 00:11:47 - TCP connection dropped - Source:64.7.205.102, 80, WAN - Destinationestination:24.121.xxx.xxx, 1974, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 00:21:59 - UDP packet dropped - Source:209.98.203.61, 137, WAN - Destination:24.121.xxx.xxx, 137, LAN - 'Suspicious UDP Data'
Mon, 03/01/2004 00:22:17 - TCP connection dropped - Source:220.255.48.56, 2811, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 00:25:01 - TCP connection dropped - Source:24.121.44.182, 4656, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 00:26:55 - TCP connection dropped - Source:200.223.240.122, 4236, WAN - Destination:24.121.xxx.xxx, 1433, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 00:31:45 - UDP packet dropped - Source:24.80.169.130, 1088, WAN - Destination:24.121.xxx.xxx, 137, LAN - 'Suspicious UDP Data'
Mon, 03/01/2004 00:34:31 - TCP connection dropped - Source:64.7.205.102, 80, WAN - Destination:24.121.xxx.xxx, 1717, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 00:39:53 - TCP connection dropped - Source:220.85.119.67, 3287, WAN - Destination:24.121.xxx.xxx, 901, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 00:47:09 - TCP connection dropped - Source:221.197.153.89, 3331, WAN - Destination:24.121.xxx.xxx, 80, LAN - 'WEB'
Mon, 03/01/2004 00:49:25 - TCP connection dropped - Source:222.100.57.163, 2490, WAN - Destination:24.121.xxx.xxx, 901, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 01:01:11 - TCP connection dropped - Source:24.121.46.234, 4047, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 01:02:43 - TCP connection dropped - Source:24.120.206.28, 1252, WAN - Destination:24.121.xxx.xxx, 8866, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 01:10:33 - TCP connection dropped - Source:218.47.19.10, 3526, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 01:30:11 - UDP packet dropped - Source:24.121.40.226, 1025, WAN - Destination:24.121.xxx.xxx, 137, LAN - 'Suspicious UDP Data'
Mon, 03/01/2004 01:33:39 - TCP connection dropped - Source:24.121.61.224, 4722, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 01:51:45 - TCP connection dropped - Source:64.7.205.102, 80, WAN - Destination:24.121.xxx.xxx, 1932, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 01:57:13 - TCP connection dropped - Source:219.162.216.125, 3331, WAN - Destination:24.121.xxx.xxx, 80, LAN - 'WEB'
Mon, 03/01/2004 02:01:35 - TCP connection dropped - Source:211.202.209.234, 4677, WAN - Destination:24.121.xxx.xxx, 901, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 02:28:18 - TCP connection dropped - Source:24.214.100.201, 63715, WAN - Destination:24.121.xxx.xxx, 901, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 02:32:20 - TCP connection dropped - Source:24.121.61.224, 4535, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 02:38:32 - TCP connection dropped - Source:64.7.205.102, 80, WAN - Destination:24.121.xxx.xxx, 1457, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 02:46:48 - UDP packet dropped - Source:65.59.64.107, 7634, WAN - Destination:24.121.xxx.xxx, 1026, LAN - 'Suspicious UDP Data'
Mon, 03/01/2004 02:47:48 - TCP connection dropped - Source:64.7.205.102, 80, WAN - Destination:24.121.xxx.xxx, 1630, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 02:55:34 - UDP packet dropped - Source:24.164.36.33, 8228, WAN - Destination:24.121.xxx.xxx, 12596, LAN - 'Suspicious UDP Data'
Mon, 03/01/2004 02:55:48 - TCP connection dropped - Source:65.105.136.188, 3430, WAN - Destination:24.121.xxx.xxx, 3389, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 03:07:20 - TCP connection dropped - Source:64.7.205.102, 80, WAN - Destination:24.121.xxx.xxx, 1143, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 03:07:38 - TCP connection dropped - Source:193.6.48.64, 1855, WAN - Destination:24.121.xxx.xxx, 3127, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 03:16:02 - TCP connection dropped - Source:200.117.214.80, 61898, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 03:16:40 - TCP connection dropped - Source:24.107.199.171, 220, WAN - Destination:24.121.xxx.xxx, 6129, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 03:28:22 - TCP connection dropped - Source:220.220.145.44, 2628, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 03:35:12 - TCP connection dropped - Source:217.207.184.195, 58565, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 03:35:24 - TCP connection dropped - Source:24.108.76.187, 3148, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 03:44:16 - TCP connection dropped - Source:24.68.215.151, 2196, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 03:44:16 - TCP connection dropped - Source:24.68.215.151, 2198, WAN - Destination:24.121.xxx.xxx, 139, LAN - 'NetBIOS'
Mon, 03/01/2004 03:44:26 - TCP connection dropped - Source:24.68.215.151, 2198, WAN - Destination:24.121.xxx.xxx, 139, LAN - 'Possible Port Scan'
Mon, 03/01/2004 03:45:30 - TCP connection dropped - Source:24.88.180.78, 3129, WAN - Destination:24.121.xxx.xxx, 27374, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 03:55:46 - TCP connection dropped - Source:64.7.205.102, 80, WAN - Destination:24.121.xxx.xxx, 1440, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 03:58:56 - TCP connection dropped - Source:141.158.29.183, 3409, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 04:18:28 - TCP connection dropped - Source:64.7.205.102, 80, WAN - Destination:24.121.xxx.xxx, 1415, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 04:32:50 - TCP connection dropped - Source:80.134.123.62, 2432, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'
Mon, 03/01/2004 04:33:34 - TCP connection dropped - Source:195.62.141.6, 2577, WAN - Destination:24.121.xxx.xxx, 3127, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 04:38:04 - TCP connection dropped - Source:64.7.205.102, 80, WAN - Destination:24.121.xxx.xxx, 1929, LAN - 'Suspicious TCP Data'
Mon, 03/01/2004 04:40:22 - UDP packet dropped - Source:24.164.33.248, 13796, WAN - Destination:24.121.xxx.xxx, 1026, LAN - 'Suspicious UDP Data'
Mon, 03/01/2004 04:42:08 - TCP connection dropped - Source:212.244.70.21, 1669, WAN - Destination:24.121.xxx.xxx, 21, LAN - 'FTP-ctrl'
Mon, 03/01/2004 04:53:00 - TCP connection dropped - Source:65.65.97.41, 2863, WAN - Destination:24.121.xxx.xxx, 139, LAN - 'NetBIOS'
Mon, 03/01/2004 05:00:28 - TCP connection dropped - Source:24.121.61.166, 1250, WAN - Destination:24.121.xxx.xxx, 445, LAN - 'SMB'