We are seeing a large number of tcp connection attempts to ports known to have 
security issues. The source addresses are spoofed from our address range. They 
are easy to block at our border router obviously, but the number and volume is 
a bit worrisome. Our upstream providers appear to be uninterested in tracing or 
blocking them. Is this the new normal? One of my concerns is that if others are 
seeing probe attempts, they will see them from these addresses and of course, 
contact us.

Any suggestions on what to do next? Or just ignore.

----
Matthew Huff       | One Manhattanville Rd
OTA Management LLC | Purchase, NY 10577
http://www.ox.com  | Phone: 914-460-4039
aim: matthewbhuff  | Fax:   914-460-4139



Reply via email to