<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Firewall log, is this attack or?]]></title><description><![CDATA[<p dir="auto">Hello, i have a question about the security and my settings that i'm using in Pfsense.<br />
I'm only using it for 2 weeks, for now i think that i  understand most i'm doing but not for sure.</p>
<p dir="auto">When i look into my firewall log, i see like 100 different ip's trying to connect to my network in some hours time..<br />
At some point i see that in one minute various different hosts trying to connect on my ip using port 61504 UDP.<br />
When i lookup that hosts, i see they are from asia, but those are blocked by Pfblocker.</p>
<p dir="auto">Ports they trying to connect to:</p>
<p dir="auto">26782 UDP<br />
445 TCP:S<br />
1214 UDP &lt;- also happens alot<br />
1214 TCP:S<br />
23 TCP:S<br />
1433 TCP:S<br />
137 UDP<br />
and some more</p>
<p dir="auto">One ip spammed the log also +- 50x from source port 37 to 169.254.255.255:137 UDP</p>
<p dir="auto">Since this night i got 400 logs like those above.</p>
<p dir="auto">I also have a mailserver in my network, all needed ports are open to that server, 25-143-993-465, also port 80 for webmail.<br />
I noticed that my mailserver blocked 6 hosts in the last weeks trying to login tho the webmail.</p>
<p dir="auto">I have no packets installed, only PFblocker with active lists:</p>
<ul>
<li>top spammer</li>
<li>whole africa</li>
<li>whole Asia</li>
<li>I-blocklist spyware</li>
<li>I-blocklist hijacked</li>
<li>I-blocklist microsoft</li>
</ul>
<p dir="auto">Do i need to do something?</p>
<p dir="auto">Sorry for bad english and thanks in advance.</p>
<p dir="auto">Stijn</p>
]]></description><link>https://forum.netgate.com/topic/54698/firewall-log-is-this-attack-or</link><generator>RSS for Node</generator><lastBuildDate>Sun, 08 Mar 2026 09:49:49 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/54698.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 29 Mar 2013 09:38:25 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Firewall log, is this attack or? on Fri, 29 Mar 2013 14:15:26 GMT]]></title><description><![CDATA[<p dir="auto">It's normally at random. If I pasted my blocked logged for just a couple minutes I'd have to use pastebin which even then their free limit might be reached. I normally do not monitor blocked traffic until I'm diagnosing an issue.</p>
]]></description><link>https://forum.netgate.com/post/387228</link><guid isPermaLink="true">https://forum.netgate.com/post/387228</guid><dc:creator><![CDATA[[[global:guest]]]]></dc:creator><pubDate>Fri, 29 Mar 2013 14:15:26 GMT</pubDate></item><item><title><![CDATA[Reply to Firewall log, is this attack or? on Fri, 29 Mar 2013 12:39:55 GMT]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">cannot say much about the other ports but 169.254.x.x looks like APIPA addresses for hosts which did not get an address by DHCP.<br />
http://en.wikipedia.org/wiki/Link-local_address</p>
<p dir="auto">And if you are running a server with open ports for mail and http I think it is very common that you get many tries from bots on the internet which check for available services.</p>
]]></description><link>https://forum.netgate.com/post/387214</link><guid isPermaLink="true">https://forum.netgate.com/post/387214</guid><dc:creator><![CDATA[Nachtfalke]]></dc:creator><pubDate>Fri, 29 Mar 2013 12:39:55 GMT</pubDate></item></channel></rss>