Jump to content

Help! Abnormal Connections


tingtongmakmak

Recommended Posts

The following connections were logged by ZoneAlarm and has been happening for over 2 weeks. I admit I am clueless as to what they mean. They appear to be incoming UDP connections scanning from lower ports to higher ports of my router IP of 192.168.11.1 to 239.255.255.250:1900 at an interval of 30 seconds.

Can anyone give me an idea of what's going on? Many thanks in advance.

FWIN,2006/03/07,15:34:38 +8:00 GMT,192.168.11.1:18399,239.255.255.250:1900,UDP

FWIN,2006/03/07,15:34:38 +8:00 GMT,192.168.11.1:18400,239.255.255.250:1900,UDP

FWIN,2006/03/07,15:34:38 +8:00 GMT,192.168.11.1:18401,239.255.255.250:1900,UDP

FWIN,2006/03/07,15:34:38 +8:00 GMT,192.168.11.1:18402,239.255.255.250:1900,UDP

FWIN,2006/03/07,15:34:38 +8:00 GMT,192.168.11.1:18403,239.255.255.250:1900,UDP

FWIN,2006/03/07,15:34:38 +8:00 GMT,192.168.11.1:18404,239.255.255.250:1900,UDP

FWIN,2006/03/07,15:34:38 +8:00 GMT,192.168.11.1:18405,239.255.255.250:1900,UDP

FWIN,2006/03/07,15:34:38 +8:00 GMT,192.168.11.1:18406,239.255.255.250:1900,UDP

FWIN,2006/03/07,15:35:08 +8:00 GMT,192.168.11.1:18407,239.255.255.250:1900,UDP

FWIN,2006/03/07,15:35:08 +8:00 GMT,192.168.11.1:18408,239.255.255.250:1900,UDP

FWIN,2006/03/07,15:35:08 +8:00 GMT,192.168.11.1:18409,239.255.255.250:1900,UDP

FWIN,2006/03/07,15:35:08 +8:00 GMT,192.168.11.1:18410,239.255.255.250:1900,UDP

FWIN,2006/03/07,15:35:08 +8:00 GMT,192.168.11.1:18411,239.255.255.250:1900,UDP

FWIN,2006/03/07,15:35:08 +8:00 GMT,192.168.11.1:18412,239.255.255.250:1900,UDP

FWIN,2006/03/07,15:35:08 +8:00 GMT,192.168.11.1:18413,239.255.255.250:1900,UDP

FWIN,2006/03/07,15:35:08 +8:00 GMT,192.168.11.1:18414,239.255.255.250:1900,UDP

FWIN,2006/03/07,15:35:08 +8:00 GMT,192.168.11.1:18415,239.255.255.250:1900,UDP

FWIN,2006/03/07,15:35:38 +8:00 GMT,192.168.11.1:18416,239.255.255.250:1900,UDP

FWIN,2006/03/07,15:35:38 +8:00 GMT,192.168.11.1:18417,239.255.255.250:1900,UDP

FWIN,2006/03/07,15:35:38 +8:00 GMT,192.168.11.1:18418,239.255.255.250:1900,UDP

Edited by tingtongmakmak
Link to comment
Share on other sites


I assume that the IP address of your gateway is 192.168.1.1. The detections ZoneAlarm gives are requests from your WAN-server to your LAN. It aren't threats as far as I know. It's a part of WAN-LAN connectivity detected by your specific firewall.

Read more about this on http://www.iana.org/faqs/abuse-faq.htm

Petch01

Thanks for the reply and information. My gateway IP is 192.168.1.1

It would appear that the incoming source IP is a multicast stream. Any idea on whether such datagram is originated from an application installed on my computer? perhaps a video/audio streaming application?

Also, why would my firewall detect transmition to and from my gateway? I thought since the firewall is installed on my pc, it would only detect things from and to my pc's IP, which is 192.168.1.2.

Would appreciate any advice.

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.








×
×
  • Create New...
""