Port Scan Activity
Hello,
I have had a FWG for some time now and I am running 1.982. I'm in the UK and have recently upgraded my WAN connection to FTTP. I am quite surprised over the amount of port scans I am subject to. I used to get a couple a month, I'm now having around 10 per day. Whilst I can't stop people/bots etc knocking on the door. Is there anything I should be doing? I do to a security lookup to see if anything come up but usually nothing. I do run a WG VPN server so the associated ports are open but...
What are you doing when you get a Port Scan alarm?
Thanks
-
Hi there,
Please double check that your Ingress Firewall is enabled: https://help.firewalla.com/hc/en-us/articles/360049856394-A-Secure-and-Better-Network-with-Firewalla-Part-3-Protect#h_01GHCCR9W6X3DPJ0GXQ2BA76KD
If the sources are external, and you have no related SSH Password Guessing Alarms at the same time, they are likely just common Internet activity. As long as your Ingress Firewall is enabled, and you don't have open external ports, Firewalla will block all attempts from reaching your internal network.
We do have a few recommended tips and steps to try: https://help.firewalla.com/hc/en-us/articles/48455312216595-Handling-Specific-Firewalla-Alarms#h_01KFM2GJ7B9RFHWPDXYN8RTKHQ
-
Hi, yes, Ingress is enabled. No SSH alarms.
I only really posted this to see what else can be done. I suppose the answer is nothing really. Firewalla is doing what it's meant todo. The only open ports are the vpn server ports, which I can't do anything about. I do feel safe and it's certainly a better device than the default ISP supplied device.
Please sign in to leave a comment.
Comments
3 comments