MN-700 Log Concern

Archived from groups: microsoft.public.broadbandnet.hardware (More info?)

Hi I was setting up my MN-700 and noticed the following
in the log file:
(I have changed X = my current IP / 1 = unknown IP)

2004/06/04 10:47:50 ** Unauthorized HTTP Access **
<IP/TCP> 11.111.111.11:3991 ->> XX.XXX.XX.XX:80

2004/06/04 10:47:53 ** Unauthorized HTTP Access **
<IP/TCP> 11.111.111.11:3991 ->> XX.XXX.XX.XX:80

2004/06/04 10:47:59 ** Unauthorized HTTP Access **
<IP/TCP> 11.111.111.11:3991 ->> XX.XXX.XX.XX:80

2004/06/04 15:19:11 ** Unauthorized HTTP Access **
<IP/TCP> 11.111.111.11:2846 ->> XX.XX.XX.XX:80

2004/06/04 15:19:11 ** Port Scan ** Port scanning from
11.111.111.11 detected


Is this regular traffic? or should I be concerned?
especially about the "port scan"??

Things to note:
Virtual DMZ is NOT checked (empty)
Mac & Client Filter is not set up.
Port forwarding is not set up.
Block ICMP Commands IS checked (enabled)
Base station mode = Router
Wireless set to 128 WEP encryption.

not sure If I have left anything out. just want to know
if that log is showing that the router is doing its job
and blocking unwanted guests, or if I have a problem with
my set-up. (modem <---> Router <---> computer)

Thanks.

ROb.
3 answers Last reply
More about concern
  1. Archived from groups: microsoft.public.broadbandnet.hardware (More info?)

    The log is showing attempts that have failed.

    --
    Jason Tsang - Microsoft MVP

    Find out about the MS MVP Program -
    http://mvp.support.microsoft.com/default.aspx

    "Rob" <anonymous@discussions.microsoft.com> wrote in message
    news:1861701c44a81$61e65c60$a401280a@phx.gbl...
    > Hi I was setting up my MN-700 and noticed the following
    > in the log file:
    > (I have changed X = my current IP / 1 = unknown IP)
    >
    > 2004/06/04 10:47:50 ** Unauthorized HTTP Access **
    > <IP/TCP> 11.111.111.11:3991 ->> XX.XXX.XX.XX:80
    >
    > 2004/06/04 10:47:53 ** Unauthorized HTTP Access **
    > <IP/TCP> 11.111.111.11:3991 ->> XX.XXX.XX.XX:80
    >
    > 2004/06/04 10:47:59 ** Unauthorized HTTP Access **
    > <IP/TCP> 11.111.111.11:3991 ->> XX.XXX.XX.XX:80
    >
    > 2004/06/04 15:19:11 ** Unauthorized HTTP Access **
    > <IP/TCP> 11.111.111.11:2846 ->> XX.XX.XX.XX:80
    >
    > 2004/06/04 15:19:11 ** Port Scan ** Port scanning from
    > 11.111.111.11 detected
    >
    >
    > Is this regular traffic? or should I be concerned?
    > especially about the "port scan"??
    >
    > Things to note:
    > Virtual DMZ is NOT checked (empty)
    > Mac & Client Filter is not set up.
    > Port forwarding is not set up.
    > Block ICMP Commands IS checked (enabled)
    > Base station mode = Router
    > Wireless set to 128 WEP encryption.
    >
    > not sure If I have left anything out. just want to know
    > if that log is showing that the router is doing its job
    > and blocking unwanted guests, or if I have a problem with
    > my set-up. (modem <---> Router <---> computer)
    >
    > Thanks.
    >
    > ROb.
    >
    >
    >
  2. Archived from groups: microsoft.public.broadbandnet.hardware (More info?)

    So does that mean no worries? or that they'll just keep
    trying till they get through. Just not really clear on
    how a router works.

    Does it fool the attackers into thinking nothing is here?

    Rob


    >-----Original Message-----
    >The log is showing attempts that have failed.
    >
    >--
    >Jason Tsang - Microsoft MVP
    >
    >Find out about the MS MVP Program -
    >http://mvp.support.microsoft.com/default.aspx
    >
    >"Rob" <anonymous@discussions.microsoft.com> wrote in
    message
    >news:1861701c44a81$61e65c60$a401280a@phx.gbl...
    >> Hi I was setting up my MN-700 and noticed the following
    >> in the log file:
    >> (I have changed X = my current IP / 1 = unknown IP)
    >>
    >> 2004/06/04 10:47:50 ** Unauthorized HTTP Access **
    >> <IP/TCP> 11.111.111.11:3991 ->> XX.XXX.XX.XX:80
    >>
    >> 2004/06/04 10:47:53 ** Unauthorized HTTP Access **
    >> <IP/TCP> 11.111.111.11:3991 ->> XX.XXX.XX.XX:80
    >>
    >> 2004/06/04 10:47:59 ** Unauthorized HTTP Access **
    >> <IP/TCP> 11.111.111.11:3991 ->> XX.XXX.XX.XX:80
    >>
    >> 2004/06/04 15:19:11 ** Unauthorized HTTP Access **
    >> <IP/TCP> 11.111.111.11:2846 ->> XX.XX.XX.XX:80
    >>
    >> 2004/06/04 15:19:11 ** Port Scan ** Port scanning from
    >> 11.111.111.11 detected
    >>
    >>
    >> Is this regular traffic? or should I be concerned?
    >> especially about the "port scan"??
    >>
    >> Things to note:
    >> Virtual DMZ is NOT checked (empty)
    >> Mac & Client Filter is not set up.
    >> Port forwarding is not set up.
    >> Block ICMP Commands IS checked (enabled)
    >> Base station mode = Router
    >> Wireless set to 128 WEP encryption.
    >>
    >> not sure If I have left anything out. just want to
    know
    >> if that log is showing that the router is doing its job
    >> and blocking unwanted guests, or if I have a problem
    with
    >> my set-up. (modem <---> Router <---> computer)
    >>
    >> Thanks.
    >>
    >> ROb.
    >>
    >>
    >>
    >
    >
    >.
    >
  3. Archived from groups: microsoft.public.broadbandnet.hardware (More info?)

    this link will tell you more about what the entries you are seeing mean.

    http://www.microsoft.com/hardware/broadbandnetworking/10_concept_log_file.mspx

    Rob wrote:

    > So does that mean no worries? or that they'll just keep
    > trying till they get through. Just not really clear on
    > how a router works.
    >
    > Does it fool the attackers into thinking nothing is here?
    >
    > Rob
    >
    >
    >
    >
    >>-----Original Message-----
    >>The log is showing attempts that have failed.
    >>
    >>--
    >>Jason Tsang - Microsoft MVP
    >>
    >>Find out about the MS MVP Program -
    >>http://mvp.support.microsoft.com/default.aspx
    >>
    >>"Rob" <anonymous@discussions.microsoft.com> wrote in
    >
    > message
    >
    >>news:1861701c44a81$61e65c60$a401280a@phx.gbl...
    >>
    >>>Hi I was setting up my MN-700 and noticed the following
    >>>in the log file:
    >>>(I have changed X = my current IP / 1 = unknown IP)
    >>>
    >>>2004/06/04 10:47:50 ** Unauthorized HTTP Access **
    >>><IP/TCP> 11.111.111.11:3991 ->> XX.XXX.XX.XX:80
    >>>
    >>>2004/06/04 10:47:53 ** Unauthorized HTTP Access **
    >>><IP/TCP> 11.111.111.11:3991 ->> XX.XXX.XX.XX:80
    >>>
    >>>2004/06/04 10:47:59 ** Unauthorized HTTP Access **
    >>><IP/TCP> 11.111.111.11:3991 ->> XX.XXX.XX.XX:80
    >>>
    >>>2004/06/04 15:19:11 ** Unauthorized HTTP Access **
    >>><IP/TCP> 11.111.111.11:2846 ->> XX.XX.XX.XX:80
    >>>
    >>>2004/06/04 15:19:11 ** Port Scan ** Port scanning from
    >>>11.111.111.11 detected
    >>>
    >>>
    >>>Is this regular traffic? or should I be concerned?
    >>>especially about the "port scan"??
    >>>
    >>>Things to note:
    >>>Virtual DMZ is NOT checked (empty)
    >>>Mac & Client Filter is not set up.
    >>>Port forwarding is not set up.
    >>>Block ICMP Commands IS checked (enabled)
    >>>Base station mode = Router
    >>>Wireless set to 128 WEP encryption.
    >>>
    >>>not sure If I have left anything out. just want to
    >
    > know
    >
    >>>if that log is showing that the router is doing its job
    >>>and blocking unwanted guests, or if I have a problem
    >
    > with
    >
    >>>my set-up. (modem <---> Router <---> computer)
    >>>
    >>>Thanks.
    >>>
    >>>ROb.
    >>>
    >>>
    >>>
    >>
    >>
    >>.
    >>
Ask a new question

Read More

Routers IP TCP/IP Networking