Jump to content

Recommended Posts

Posted

Every day for the last couple of weeks I get 50/60 firewall events

from IP 203.151.21.63 which traces back to Internet Thailand

Company Limited.

Protocol ICMP, destination 192.168.1.5 source port (type3)

destination port (type 10).

Does anyone out there know this company and why they

would be trying to get through my firewall??

I have sent them an e mail to stop what ever they are trying

to do, but every day more and more attempts from them are

blocked by my firewall.

any help would be welcome regards Worgeordie

Posted

Are these alerts popping up on the screen? If they are, alter your firewall setting to stop showing the alerts.

Apart from that, I see no problem. As said above it is most likely your ISP pinging the computer.

IP address: 203.151.21.63 IP country: th.png Thailand IP Address state: Krung Thep IP Address city: Bangkok IP latitude: 13.7500 IP longitude: 100.5167 ISP: Internet Thailand Company Limited Organization: INET Datacenter net Host: host63.truehits.net

So no problems. OK?

Posted

Be careful.

Once I set up my firewall to block pings and the ISP dropped the connection after a few minutes

and I had to reconnect, a real pain.

Posted

One should not block pings (IMO) but instead disable notifications from your firewall.

Every computer that is exposed to the Internet is scanned at least a dozen of times per day. If your firewall is to alert you every time, this will be a nuisance.

When the alert pops up, most firewalls have an option like "don't alert me next time for similar connections". Use it.

Note: blocking ICMPs altogether (not only pings) is a very bad idea. Some essential parts of the TCP/IP protocol (path MTU discovery) rely on the ability for your computer to receive specific kinds of ICMPs. Random connections will fail on a computer that doesn't receive ICMPs at all.

Posted

I have a similar problem except my 'intrusions' come from numerous different IP adresses from around the world. My Internet security blocks them as Packets with incorrect SYN, ACK and FIN combinations. Any idea what this could be? Is it possibly something to do with Torrents I am downloading?

Posted

Remove your sensationalist firewall software. Then don't worry about this.

All this is is your firewall software reminding you how very important it is. So you don't get ideas, like the Windows built in firewall is actually just as good, and the need for a firewall is questionable anyway if you're sitting behind a DSL modem/router which has a built in one... I mean keep it turned on but just use the Windows one that came with your OS.

Posted

Well I have tried all your suggestions, Except turn off or remove the firewall !! not a good idea

The intrusions are not from TOT my Internet provider, and I believe they are from a private

company, Internet Thailand Company Ltd. Bangkok

I have just booted up a few minutes ago and my firewall tells me that there has been 64 attempts

already.

regards Worgeordie

Posted

you could try to allow them to ping you once then reblock/redrop those packets and check the logs. it's possible you're receiving all these because they can't reach you in the first place.

Posted

Hi urandom, What I want to know is why they are trying to access my

computer in the first place, I dont know them, yesterday it was 134

attempts ,I have never had this problem before,

regards Worgeordie

Posted

they're not trying to "access your computer", they're just checking if the host is up. this is neither illegal nor risky at this point. also, this IP address is an inet server. It is possible that they have some bandwith buying/selling deal with your ISP. if you're feeling adventurous, just call your ISP, ask to talk to an engineer and ask him if it's normal.

Posted

Well I have tried all your suggestions, Except turn off or remove the firewall !! not a good idea

The intrusions are not from TOT my Internet provider, and I believe they are from a private

company, Internet Thailand Company Ltd. Bangkok

I have just booted up a few minutes ago and my firewall tells me that there has been 64 attempts

already.

regards Worgeordie

They are not trying to access your computer or steal your data or anything malicious.

Simply go to your preferences and turn off the notifications!

All our computers are pinged, not only yours. My firewall has logged 56,580 access attempts in a little over 3 months. No problem. Most are my ISP pinging me.

Now go and enjoy life, there are more important things in life :)

Posted

Well Pleased to report that so far today have

had no intrusions from them.so hope things

go back to normal for me.

Its just that I never get intrusion attempts on

my firewall, and not been knowledgeable about

computers and their workings,it made me a bit

paranoid..So thanks everyone for your help

regards Worgeordie.

Posted

All our computers are pinged, not only yours. My firewall has logged 56,580 access attempts in a little over 3 months.

What a waste of bandwidth. :whistling:

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.


×
×
  • Create New...