Ntop - Flow Floods



  • Hi

    I've noticed a few messages in pfsenses system.log and in ntops alerts stating

    Host x.x.x.x is possibly under scan attack [65536 active flows]
    

    And then a short while later

    Host x.x.x.x. is no longer under scan attack [65536 active flows]
    

    Can anyone explain what it means and what I need to do to stop it ?
    Thanks



  • Seeing the same error. The IP is behind the firewall so this could only be happening from an internal IP, maybe the bridge?
    Any possibility to see what source IP triggered this?