Go Back   PCMech Forums > Help & Discussion > Networking & Online Security

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 03-30-2003, 02:08 AM   #1
Member (9 bit)
 
Join Date: Dec 2002
Location: Kansas City, MO U.S.A.
Posts: 404
What are all these TCP Packets Being Dropped by My Router?

Just bought a Netgear firewall (SPI)/Router. In the router's security log, there are several TCP packets that are listed as dropped. What are all these packets coming to me? Is someone pinging me? Or are these packets coming from my ISP?

BTW...using SBC DSL.
Preston is offline   Reply With Quote
Old 03-30-2003, 04:25 AM   #2
Member (8 bit)
 
jackjones's Avatar
 
Join Date: Apr 2002
Posts: 153
It is totally impossible to tell you anything about the packets that your Router is dropping and why you are recieving them when you don't give us anymore information. I would whoever not give it a second thought if I were you. The internet is full of "noise".
jackjones is offline   Reply With Quote
Old 03-30-2003, 01:24 PM   #3
Member (9 bit)
 
Join Date: Dec 2002
Location: Kansas City, MO U.S.A.
Posts: 404
Some of these packets are UDP and some TCP....there are several entries in the log saying that a packet was dropped from an IP address (several different ones) because of default inbound rule (which says to block all inbound services)...

Some of the sources are:

Source:12.7.210.242
Source:12.211.244.219
Source:61.6.137.46

Is this a normal to see all these inbound packets being dropped by the firewall? (This is my first SPI firewall).


Preston
Preston is offline   Reply With Quote
Old 03-31-2003, 02:39 PM   #4
Member (8 bit)
 
jackjones's Avatar
 
Join Date: Apr 2002
Posts: 153
yes, it's very normal.
jackjones is offline   Reply With Quote
Old 03-31-2003, 11:08 PM   #5
Member (9 bit)
 
Join Date: Dec 2002
Location: Kansas City, MO U.S.A.
Posts: 404
Are thes 'pings' from other people, the so called door rattlers? Or something from my ISP?
Preston is offline   Reply With Quote
Old 03-31-2003, 11:33 PM   #6
Member (12 bit)
 
Redo40's Avatar
 
Join Date: Jan 2002
Location: Central Arkansas
Posts: 2,170
Could be both. In most cases, it's not anything to worry about.
__________________
Roger

"Our greatest glory is not in never falling, but in rising every time we fall."
-Confucius
Redo40 is offline   Reply With Quote
Old 04-01-2003, 06:54 AM   #7
I am, in reality, a moose
Staff
Premium Member
 
mbossman2's Avatar
 
Join Date: Aug 1999
Location: RTP, NC
Posts: 2,441
with stateful firewalls, most unsolicited packets are just dropped as the can not pass the security checks of the firewall unless you allow for such traffic (like you are hosting a website).

Don't get too obsessed with the security logs, there is so much traffic out there that just plain old does not concern you that if you investigate every entry in the log, you will never have time to do anything else.

(of course you can ignore this unless your ultimate goal is to become an internet security guru and then, by all means dig thru the logs and find out everything that you can).
mbossman2 is offline   Reply With Quote
Old 04-01-2003, 11:52 AM   #8
Member (10 bit)
 
jeresimo's Avatar
 
Join Date: Jun 1999
Location: Massachusetts-Spirit of America
Posts: 893
If you want to verify those IP numbers, you could DL a free utility called Neo Express and satisfy your curiousity.
jeresimo is offline   Reply With Quote
Old 04-02-2003, 09:39 PM   #9
Member (9 bit)
 
Join Date: Dec 2002
Location: Kansas City, MO U.S.A.
Posts: 404
Neo Express...do you have link for that one? Couldn't find it...
Preston is offline   Reply With Quote
Old 04-03-2003, 11:56 AM   #10
Member (10 bit)
 
jeresimo's Avatar
 
Join Date: Jun 1999
Location: Massachusetts-Spirit of America
Posts: 893
http://web.utanet.at/peuker/schutz.htm

Scroll down and look for NEO TRACE EXPRESS (but I suggest you scan it with your AV before installing it. I can not vouch for the integrity of the site though)

(Note to Moderator: Pls feel free to delete this post if you think this is not proper to be posted here)
jeresimo is offline   Reply With Quote
Old 04-08-2003, 10:55 PM   #11
Member (9 bit)
 
Join Date: Dec 2002
Location: Kansas City, MO U.S.A.
Posts: 404
Sorry to bump this one back up, but...

Wow....don't get me wrong, I'm not obsessing over these security logs (just trying to understand what's going on out there), but there have been a couple of hundred of dropped packets over the past 24 hours!

Even if they are harmless, it's darn nice to have this firewall! Should have gotten one a long time ago. Have to say I second all the recommendations for firewalls.

I didn't have any luck finding Neo Trace, but I did grab 'nslook' from the PC Pitstop website....these packets are coming from all over the place....many of them from non-english websites.....
Preston is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 07:22 PM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 PL2