Aces High Bulletin Board
General Forums => Hardware and Software => Topic started by: CavemanJ on October 21, 2003, 12:18:48 AM
-
Ok, so I go raid the kitchen for a quick midnight snack, and as I come out of the kitchen I notice the WAN light on my router and the activity light on the cable modem are both blinking faster than a 262 running from a squadron of Ponies.
The lights for the boxes plugged into the router are steady, showing no activity on my LAN, but just to be sure I pulled the cables for about 10 minutes to see.. and the WAN/activity lights just kept right on going. So I'm guessing this is something from the net trying to get to my LAN and stopping at the firewall.
So what I want to know is, how can I find out what this activity is without opening up the network? The security log in the router only shows login attempts and when the router/modem renew the IP.
-
Caveman, it may not be anyone trying to "get in" to your LAN.
You may have gotten an IP from a Kazaa (or any file sharing program) user and you are getting hit by the other Kazaa users. This usually will subside in about 24 to 48 hours. This is probably the most likely due to the number of these users on the Internet. Bandwidth hogs.
Or, there could be other users on your subnet who are running with file and printer sharing and your LAN is being hit by all the various probes MS sends out to the subnet when announcing itself and searching for the other nodes on the subnet. This will be sporadic and mostly effects cable networks, due to the network architecture.
Or, someone on your subnet is running a program that has to do a broadcast and you are getting hit.
SPAMMERS hit port 25 of every IP address on the Internet, continually, so this could be it. They are just looking for open relays. Sick lot.
If your firewall is doing any logging, then you have the IP address. You can go to http://www.arin.net and find which ISP owns that IP address.
-
Thanks Skuzzy. The router has a security log, but it only logs attempts to log into it and the DHCP client stuff for when it renews the IP from the ISP, which is cable.
So I'm gonna guess if I really wanna find out what it is I'd have to open the network? It'll forever remain a mystery then =)
-
What kind of router you running Cave?
-
It's an SMC Barricade, SMC7004ABR (http://www.smc.com/index.cfm?sec=Products&pg=Product-Details&prod=67&site=c)
-
Could be viruses, too. If you have hacked boxes in your network they'll do continuous port scans in order to infect other machines.
-
Originally posted by Siaf__csf
Could be viruses, too. If you have hacked boxes in your network they'll do continuous port scans in order to infect other machines.
Nope, no traffic on the LAN at all. Just something tickling the router from the net.
-
I meant your ISP's network.
-
Cave my cable modem been same way since the blaster worm hit the net,,,, constant activity, but no entrance, and no conx issues.
Even changed my wan IP several times and no difference.