Strange traffic in states table
-
What exactly does this mean?
tcp 127.0.0.1:19004 <- "our external ip":80 <- 192.168.1.115:63933
(I replaced our actual IP with the words)
We have been having problems with this user playing WOW and a few other things on the clock. He got caught recently and now my states table is full of hundreds of these. What is he up to? Does this mean they set up a tunnel through port 80 (that was a suggestion from someone else who saw this)?
Thanks
Bob
-
That is how a normal NAT entry looks.
That means that someone on 192.168.1.115 connected to your external port 80 and was redirected to 127.0.0.1:19004.
That looks like you have NAT reflection enabled, and you have a port forward on port 80 to some other internal host.
-
Ok thanks.