MN-700 Log Concern

Rob

Distinguished
Dec 31, 2007
1,573
0
19,780
Archived from groups: microsoft.public.broadbandnet.hardware (More info?)

Hi I was setting up my MN-700 and noticed the following
in the log file:
(I have changed X = my current IP / 1 = unknown IP)

2004/06/04 10:47:50 ** Unauthorized HTTP Access **
<IP/TCP> 11.111.111.11:3991 ->> XX.XXX.XX.XX:80

2004/06/04 10:47:53 ** Unauthorized HTTP Access **
<IP/TCP> 11.111.111.11:3991 ->> XX.XXX.XX.XX:80

2004/06/04 10:47:59 ** Unauthorized HTTP Access **
<IP/TCP> 11.111.111.11:3991 ->> XX.XXX.XX.XX:80

2004/06/04 15:19:11 ** Unauthorized HTTP Access **
<IP/TCP> 11.111.111.11:2846 ->> XX.XX.XX.XX:80

2004/06/04 15:19:11 ** Port Scan ** Port scanning from
11.111.111.11 detected


Is this regular traffic? or should I be concerned?
especially about the "port scan"??

Things to note:
Virtual DMZ is NOT checked (empty)
Mac & Client Filter is not set up.
Port forwarding is not set up.
Block ICMP Commands IS checked (enabled)
Base station mode = Router
Wireless set to 128 WEP encryption.

not sure If I have left anything out. just want to know
if that log is showing that the router is doing its job
and blocking unwanted guests, or if I have a problem with
my set-up. (modem <---> Router <---> computer)

Thanks.

ROb.
 
G

Guest

Guest
Archived from groups: microsoft.public.broadbandnet.hardware (More info?)

The log is showing attempts that have failed.

--
Jason Tsang - Microsoft MVP

Find out about the MS MVP Program -
http://mvp.support.microsoft.com/default.aspx

"Rob" <anonymous@discussions.microsoft.com> wrote in message
news:1861701c44a81$61e65c60$a401280a@phx.gbl...
> Hi I was setting up my MN-700 and noticed the following
> in the log file:
> (I have changed X = my current IP / 1 = unknown IP)
>
> 2004/06/04 10:47:50 ** Unauthorized HTTP Access **
> <IP/TCP> 11.111.111.11:3991 ->> XX.XXX.XX.XX:80
>
> 2004/06/04 10:47:53 ** Unauthorized HTTP Access **
> <IP/TCP> 11.111.111.11:3991 ->> XX.XXX.XX.XX:80
>
> 2004/06/04 10:47:59 ** Unauthorized HTTP Access **
> <IP/TCP> 11.111.111.11:3991 ->> XX.XXX.XX.XX:80
>
> 2004/06/04 15:19:11 ** Unauthorized HTTP Access **
> <IP/TCP> 11.111.111.11:2846 ->> XX.XX.XX.XX:80
>
> 2004/06/04 15:19:11 ** Port Scan ** Port scanning from
> 11.111.111.11 detected
>
>
> Is this regular traffic? or should I be concerned?
> especially about the "port scan"??
>
> Things to note:
> Virtual DMZ is NOT checked (empty)
> Mac & Client Filter is not set up.
> Port forwarding is not set up.
> Block ICMP Commands IS checked (enabled)
> Base station mode = Router
> Wireless set to 128 WEP encryption.
>
> not sure If I have left anything out. just want to know
> if that log is showing that the router is doing its job
> and blocking unwanted guests, or if I have a problem with
> my set-up. (modem <---> Router <---> computer)
>
> Thanks.
>
> ROb.
>
>
>
 

Rob

Distinguished
Dec 31, 2007
1,573
0
19,780
Archived from groups: microsoft.public.broadbandnet.hardware (More info?)

So does that mean no worries? or that they'll just keep
trying till they get through. Just not really clear on
how a router works.

Does it fool the attackers into thinking nothing is here?

Rob



>-----Original Message-----
>The log is showing attempts that have failed.
>
>--
>Jason Tsang - Microsoft MVP
>
>Find out about the MS MVP Program -
>http://mvp.support.microsoft.com/default.aspx
>
>"Rob" <anonymous@discussions.microsoft.com> wrote in
message
>news:1861701c44a81$61e65c60$a401280a@phx.gbl...
>> Hi I was setting up my MN-700 and noticed the following
>> in the log file:
>> (I have changed X = my current IP / 1 = unknown IP)
>>
>> 2004/06/04 10:47:50 ** Unauthorized HTTP Access **
>> <IP/TCP> 11.111.111.11:3991 ->> XX.XXX.XX.XX:80
>>
>> 2004/06/04 10:47:53 ** Unauthorized HTTP Access **
>> <IP/TCP> 11.111.111.11:3991 ->> XX.XXX.XX.XX:80
>>
>> 2004/06/04 10:47:59 ** Unauthorized HTTP Access **
>> <IP/TCP> 11.111.111.11:3991 ->> XX.XXX.XX.XX:80
>>
>> 2004/06/04 15:19:11 ** Unauthorized HTTP Access **
>> <IP/TCP> 11.111.111.11:2846 ->> XX.XX.XX.XX:80
>>
>> 2004/06/04 15:19:11 ** Port Scan ** Port scanning from
>> 11.111.111.11 detected
>>
>>
>> Is this regular traffic? or should I be concerned?
>> especially about the "port scan"??
>>
>> Things to note:
>> Virtual DMZ is NOT checked (empty)
>> Mac & Client Filter is not set up.
>> Port forwarding is not set up.
>> Block ICMP Commands IS checked (enabled)
>> Base station mode = Router
>> Wireless set to 128 WEP encryption.
>>
>> not sure If I have left anything out. just want to
know
>> if that log is showing that the router is doing its job
>> and blocking unwanted guests, or if I have a problem
with
>> my set-up. (modem <---> Router <---> computer)
>>
>> Thanks.
>>
>> ROb.
>>
>>
>>
>
>
>.
>
 

joker

Distinguished
Apr 12, 2004
1,064
0
19,280
Archived from groups: microsoft.public.broadbandnet.hardware (More info?)

this link will tell you more about what the entries you are seeing mean.

http://www.microsoft.com/hardware/broadbandnetworking/10_concept_log_file.mspx

Rob wrote:

> So does that mean no worries? or that they'll just keep
> trying till they get through. Just not really clear on
> how a router works.
>
> Does it fool the attackers into thinking nothing is here?
>
> Rob
>
>
>
>
>>-----Original Message-----
>>The log is showing attempts that have failed.
>>
>>--
>>Jason Tsang - Microsoft MVP
>>
>>Find out about the MS MVP Program -
>>http://mvp.support.microsoft.com/default.aspx
>>
>>"Rob" <anonymous@discussions.microsoft.com> wrote in
>
> message
>
>>news:1861701c44a81$61e65c60$a401280a@phx.gbl...
>>
>>>Hi I was setting up my MN-700 and noticed the following
>>>in the log file:
>>>(I have changed X = my current IP / 1 = unknown IP)
>>>
>>>2004/06/04 10:47:50 ** Unauthorized HTTP Access **
>>><IP/TCP> 11.111.111.11:3991 ->> XX.XXX.XX.XX:80
>>>
>>>2004/06/04 10:47:53 ** Unauthorized HTTP Access **
>>><IP/TCP> 11.111.111.11:3991 ->> XX.XXX.XX.XX:80
>>>
>>>2004/06/04 10:47:59 ** Unauthorized HTTP Access **
>>><IP/TCP> 11.111.111.11:3991 ->> XX.XXX.XX.XX:80
>>>
>>>2004/06/04 15:19:11 ** Unauthorized HTTP Access **
>>><IP/TCP> 11.111.111.11:2846 ->> XX.XX.XX.XX:80
>>>
>>>2004/06/04 15:19:11 ** Port Scan ** Port scanning from
>>>11.111.111.11 detected
>>>
>>>
>>>Is this regular traffic? or should I be concerned?
>>>especially about the "port scan"??
>>>
>>>Things to note:
>>>Virtual DMZ is NOT checked (empty)
>>>Mac & Client Filter is not set up.
>>>Port forwarding is not set up.
>>>Block ICMP Commands IS checked (enabled)
>>>Base station mode = Router
>>>Wireless set to 128 WEP encryption.
>>>
>>>not sure If I have left anything out. just want to
>
> know
>
>>>if that log is showing that the router is doing its job
>>>and blocking unwanted guests, or if I have a problem
>
> with
>
>>>my set-up. (modem <---> Router <---> computer)
>>>
>>>Thanks.
>>>
>>>ROb.
>>>
>>>
>>>
>>
>>
>>.
>>