Stuartbe
14-01-2004, 23:55
I have had multilpe hits on my firewall that apear to be broadcasts but they are not.
Does anyone have any idea on what they may be ??
---------------------------------------------------------
[13/Jan/2004 19:18:35] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:18:35] NAT: + proto:TCP, len:60, ip+port:62.253.162.51:110 -> ***.***.***.***:52089, flags: RST , seq:1070064662 ack:0, win:0, tcplen:0
[13/Jan/2004 19:25:16] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:25:16] NAT: + proto:TCP, len:60, ip+port:207.68.171.234:80 -> ***.***.***.***:52135, flags: FIN ACK , seq:2459590829 ack:265719730, win:17143, tcplen:0
[13/Jan/2004 19:27:38] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:27:38] NAT: + proto:TCP, len:1486, ip+port:212.3.243.131:80 -> ***.***.***.***:52178, flags: ACK , seq:3889359289 ack:299366628, win:7504, tcplen:1432
[13/Jan/2004 19:27:38] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:27:38] NAT: + proto:TCP, len:1486, ip+port:212.3.243.131:80 -> ***.***.***.***:52178, flags: ACK PSH , seq:3889360721 ack:299366628, win:7504, tcplen:1432
[13/Jan/2004 19:27:38] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:27:38] NAT: + proto:TCP, len:1486, ip+port:212.3.243.131:80 -> ***.***.***.***:52178, flags: ACK , seq:3889362153 ack:299366628, win:7504, tcplen:1432
[13/Jan/2004 19:27:38] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:27:38] NAT: + proto:TCP, len:1486, ip+port:212.3.243.131:80 -> ***.***.***.***:52178, flags: ACK PSH , seq:3889363585 ack:299366628, win:7504, tcplen:1432
[13/Jan/2004 19:28:37] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:28:37] NAT: + proto:TCP, len:1486, ip+port:212.3.243.131:80 -> ***.***.***.***:52194, flags: ACK , seq:3960930991 ack:315377461, win:6432, tcplen:1432
[13/Jan/2004 19:28:37] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:28:37] NAT: + proto:TCP, len:172, ip+port:212.3.243.131:80 -> ***.***.***.***:52194, flags: ACK PSH , seq:3960932423 ack:315377461, win:6432, tcplen:118
[13/Jan/2004 19:29:16] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:29:16] NAT: + proto:TCP, len:1486, ip+port:206.65.183.156:80 -> ***.***.***.***:52218, flags: ACK , seq:3990520452 ack:324829690, win:6432, tcplen:1432
[13/Jan/2004 19:29:16] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:29:16] NAT: + proto:TCP, len:1486, ip+port:206.65.183.156:80 -> ***.***.***.***:52218, flags: ACK PSH , seq:3990521884 ack:324829690, win:6432, tcplen:1432
[13/Jan/2004 19:29:16] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:29:16] NAT: + proto:TCP, len:1486, ip+port:206.65.183.156:80 -> ***.***.***.***:52218, flags: ACK , seq:3990523316 ack:324829690, win:6432, tcplen:1432
[13/Jan/2004 19:29:16] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:29:16] NAT: + proto:TCP, len:1486, ip+port:206.65.183.156:80 -> ***.***.***.***:52218, flags: ACK PSH , seq:3990524748 ack:324829690, win:6432, tcplen:1432
[13/Jan/2004 19:36:41] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:36:41] NAT: + proto:TCP, len:1486, ip+port:207.46.244.158:80 -> ***.***.***.***:52247, flags: ACK , seq:151798085 ack:426718231, win:16080, tcplen:1432
[13/Jan/2004 19:36:41] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:36:41] NAT: + proto:TCP, len:1220, ip+port:207.46.244.158:80 -> ***.***.***.***:52247, flags: ACK PSH , seq:151799517 ack:426718231, win:16080, tcplen:1166
[13/Jan/2004 19:38:31] NAT: Detected UDP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:38:31] NAT: + proto:UDP, len:342, ip+port:***.***.***.***:68 -> 255.255.255.255:67, udplen:300
[13/Jan/2004 19:38:35] NAT: Detected UDP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:38:35] NAT: + proto:UDP, len:342, ip+port:***.***.***.***:68 -> 255.255.255.255:67, udplen:300
[13/Jan/2004 19:38:40] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:38:40] NAT: + proto:TCP, len:1486, ip+port:207.46.244.158:80 -> ***.***.***.***:52256, flags: ACK , seq:300521995 ack:457437825, win:6432, tcplen:1432
[13/Jan/2004 19:38:40] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:38:40] NAT: + proto:TCP, len:1220, ip+port:207.46.244.158:80 -> ***.***.***.***:52256, flags: ACK PSH , seq:300523427 ack:457437825, win:6432, tcplen:1166
[13/Jan/2004 19:38:51] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:38:51] NAT: + proto:TCP, len:1486, ip+port:207.46.244.158:80 -> ***.***.***.***:52260, flags: ACK , seq:304907822 ack:458405739, win:16080, tcplen:1432
[13/Jan/2004 19:38:51] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:38:51] NAT: + proto:TCP, len:1220, ip+port:207.46.244.158:80 -> ***.***.***.***:52260, flags: ACK PSH , seq:304909254 ack:458405739, win:16080, tcplen:1166
[13/Jan/2004 19:40:59] NAT: Attempt to establish TCP connection through NAT (in). The following line contains suspicious packet dump:
[13/Jan/2004 19:40:59] NAT: + proto:TCP, len:60, ip+port:64.48.134.31:0 -> ***.***.***.***:35441, flags: SYN , seq:3937 ack:0, win:512, tcplen:0
[13/Jan/2004 19:45:14] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:45:14] NAT: + proto:TCP, len:654, ip+port:207.46.244.158:80 -> ***.***.***.***:52337, flags: ACK PSH , seq:717627874 ack:551898041, win:6432, tcplen:600
[13/Jan/2004 19:45:18] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:45:18] NAT: + proto:TCP, len:1486, ip+port:65.54.249.254:80 -> ***.***.***.***:52338, flags: ACK , seq:721708892 ack:553156183, win:6432, tcplen:1432
[13/Jan/2004 19:45:18] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:45:18] NAT: + proto:TCP, len:1486, ip+port:65.54.249.254:80 -> ***.***.***.***:52338, flags: ACK , seq:721710324 ack:553156183, win:6432, tcplen:1432
[13/Jan/2004 19:55:51] NAT: Detected UDP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:55:51] NAT: + proto:UDP, len:342, ip+port:***.***.***.***:68 -> 255.255.255.255:67, udplen:300
[13/Jan/2004 19:55:55] NAT: Detected UDP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:55:55] NAT: + proto:UDP, len:342, ip+port:***.***.***.***:68 -> 255.255.255.255:67, udplen:300
[13/Jan/2004 19:59:10] NAT: Detected UDP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:59:10] NAT: + proto:UDP, len:342, ip+port:***.***.***.***:68 -> 255.255.255.255:67, udplen:300
[13/Jan/2004 19:59:13] NAT: Detected UDP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
Does anyone have any idea on what they may be ??
---------------------------------------------------------
[13/Jan/2004 19:18:35] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:18:35] NAT: + proto:TCP, len:60, ip+port:62.253.162.51:110 -> ***.***.***.***:52089, flags: RST , seq:1070064662 ack:0, win:0, tcplen:0
[13/Jan/2004 19:25:16] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:25:16] NAT: + proto:TCP, len:60, ip+port:207.68.171.234:80 -> ***.***.***.***:52135, flags: FIN ACK , seq:2459590829 ack:265719730, win:17143, tcplen:0
[13/Jan/2004 19:27:38] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:27:38] NAT: + proto:TCP, len:1486, ip+port:212.3.243.131:80 -> ***.***.***.***:52178, flags: ACK , seq:3889359289 ack:299366628, win:7504, tcplen:1432
[13/Jan/2004 19:27:38] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:27:38] NAT: + proto:TCP, len:1486, ip+port:212.3.243.131:80 -> ***.***.***.***:52178, flags: ACK PSH , seq:3889360721 ack:299366628, win:7504, tcplen:1432
[13/Jan/2004 19:27:38] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:27:38] NAT: + proto:TCP, len:1486, ip+port:212.3.243.131:80 -> ***.***.***.***:52178, flags: ACK , seq:3889362153 ack:299366628, win:7504, tcplen:1432
[13/Jan/2004 19:27:38] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:27:38] NAT: + proto:TCP, len:1486, ip+port:212.3.243.131:80 -> ***.***.***.***:52178, flags: ACK PSH , seq:3889363585 ack:299366628, win:7504, tcplen:1432
[13/Jan/2004 19:28:37] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:28:37] NAT: + proto:TCP, len:1486, ip+port:212.3.243.131:80 -> ***.***.***.***:52194, flags: ACK , seq:3960930991 ack:315377461, win:6432, tcplen:1432
[13/Jan/2004 19:28:37] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:28:37] NAT: + proto:TCP, len:172, ip+port:212.3.243.131:80 -> ***.***.***.***:52194, flags: ACK PSH , seq:3960932423 ack:315377461, win:6432, tcplen:118
[13/Jan/2004 19:29:16] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:29:16] NAT: + proto:TCP, len:1486, ip+port:206.65.183.156:80 -> ***.***.***.***:52218, flags: ACK , seq:3990520452 ack:324829690, win:6432, tcplen:1432
[13/Jan/2004 19:29:16] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:29:16] NAT: + proto:TCP, len:1486, ip+port:206.65.183.156:80 -> ***.***.***.***:52218, flags: ACK PSH , seq:3990521884 ack:324829690, win:6432, tcplen:1432
[13/Jan/2004 19:29:16] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:29:16] NAT: + proto:TCP, len:1486, ip+port:206.65.183.156:80 -> ***.***.***.***:52218, flags: ACK , seq:3990523316 ack:324829690, win:6432, tcplen:1432
[13/Jan/2004 19:29:16] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:29:16] NAT: + proto:TCP, len:1486, ip+port:206.65.183.156:80 -> ***.***.***.***:52218, flags: ACK PSH , seq:3990524748 ack:324829690, win:6432, tcplen:1432
[13/Jan/2004 19:36:41] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:36:41] NAT: + proto:TCP, len:1486, ip+port:207.46.244.158:80 -> ***.***.***.***:52247, flags: ACK , seq:151798085 ack:426718231, win:16080, tcplen:1432
[13/Jan/2004 19:36:41] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:36:41] NAT: + proto:TCP, len:1220, ip+port:207.46.244.158:80 -> ***.***.***.***:52247, flags: ACK PSH , seq:151799517 ack:426718231, win:16080, tcplen:1166
[13/Jan/2004 19:38:31] NAT: Detected UDP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:38:31] NAT: + proto:UDP, len:342, ip+port:***.***.***.***:68 -> 255.255.255.255:67, udplen:300
[13/Jan/2004 19:38:35] NAT: Detected UDP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:38:35] NAT: + proto:UDP, len:342, ip+port:***.***.***.***:68 -> 255.255.255.255:67, udplen:300
[13/Jan/2004 19:38:40] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:38:40] NAT: + proto:TCP, len:1486, ip+port:207.46.244.158:80 -> ***.***.***.***:52256, flags: ACK , seq:300521995 ack:457437825, win:6432, tcplen:1432
[13/Jan/2004 19:38:40] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:38:40] NAT: + proto:TCP, len:1220, ip+port:207.46.244.158:80 -> ***.***.***.***:52256, flags: ACK PSH , seq:300523427 ack:457437825, win:6432, tcplen:1166
[13/Jan/2004 19:38:51] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:38:51] NAT: + proto:TCP, len:1486, ip+port:207.46.244.158:80 -> ***.***.***.***:52260, flags: ACK , seq:304907822 ack:458405739, win:16080, tcplen:1432
[13/Jan/2004 19:38:51] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:38:51] NAT: + proto:TCP, len:1220, ip+port:207.46.244.158:80 -> ***.***.***.***:52260, flags: ACK PSH , seq:304909254 ack:458405739, win:16080, tcplen:1166
[13/Jan/2004 19:40:59] NAT: Attempt to establish TCP connection through NAT (in). The following line contains suspicious packet dump:
[13/Jan/2004 19:40:59] NAT: + proto:TCP, len:60, ip+port:64.48.134.31:0 -> ***.***.***.***:35441, flags: SYN , seq:3937 ack:0, win:512, tcplen:0
[13/Jan/2004 19:45:14] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:45:14] NAT: + proto:TCP, len:654, ip+port:207.46.244.158:80 -> ***.***.***.***:52337, flags: ACK PSH , seq:717627874 ack:551898041, win:6432, tcplen:600
[13/Jan/2004 19:45:18] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:45:18] NAT: + proto:TCP, len:1486, ip+port:65.54.249.254:80 -> ***.***.***.***:52338, flags: ACK , seq:721708892 ack:553156183, win:6432, tcplen:1432
[13/Jan/2004 19:45:18] NAT: Detected TCP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:45:18] NAT: + proto:TCP, len:1486, ip+port:65.54.249.254:80 -> ***.***.***.***:52338, flags: ACK , seq:721710324 ack:553156183, win:6432, tcplen:1432
[13/Jan/2004 19:55:51] NAT: Detected UDP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:55:51] NAT: + proto:UDP, len:342, ip+port:***.***.***.***:68 -> 255.255.255.255:67, udplen:300
[13/Jan/2004 19:55:55] NAT: Detected UDP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:55:55] NAT: + proto:UDP, len:342, ip+port:***.***.***.***:68 -> 255.255.255.255:67, udplen:300
[13/Jan/2004 19:59:10] NAT: Detected UDP packet which has no entry in the NAT table. The following line contains suspicious packet dump:
[13/Jan/2004 19:59:10] NAT: + proto:UDP, len:342, ip+port:***.***.***.***:68 -> 255.255.255.255:67, udplen:300
[13/Jan/2004 19:59:13] NAT: Detected UDP packet which has no entry in the NAT table. The following line contains suspicious packet dump: