cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
760
Views
0
Helpful
1
Replies

Receiving a Security Alert on my WRVS4400N

nadim.batri
Level 1
Level 1

I have received the following security alert forwarded to my email several times now and would like to know what this means? Thanks in advance for your help:

Security Alert WRVS4400N

No.001  May  1 09:28:44  - [Firewall Log-PORT SCAN] UDP Packet - 10.249.209.101 --> 93.185.235.224

No.002  May  1 09:28:44  - [Firewall Log-PORT SCAN] UDP Packet - 10.249.209.101 --> 93.185.235.224

No.003  May  1 09:28:44  - [Firewall Log-PORT SCAN] UDP Packet - 10.249.209.101 --> 93.185.235.224

No.004  May  1 09:28:44  - [Firewall Log-PORT SCAN] UDP Packet - 10.249.209.101 --> 93.185.235.224

No.005  May  1 09:28:44  - [Firewall Log-PORT SCAN] UDP Packet - 10.249.209.101 --> 93.185.235.224

No.006  May  1 09:28:44  - [Firewall Log-PORT SCAN] UDP Packet - 10.249.209.101 --> 93.185.235.224

No.007  May  3 17:57:22  - [Firewall Log-PORT SCAN] TCP Packet - 107.22.70.149 --> 93.185.235.224

No.008  May  3 17:57:22  - [Firewall Log-PORT SCAN] TCP Packet - 107.22.70.149 --> 93.185.235.224

No.009  May  3 17:57:22  - [Firewall Log-PORT SCAN] TCP Packet - 107.22.70.149 --> 93.185.235.224

No.010  May  3 17:57:22  - [Firewall Log-PORT SCAN] TCP Packet - 107.22.70.149 --> 192.168.220.1

No.011  May  3 17:57:22  - [Firewall Log-PORT SCAN] TCP Packet - 107.22.70.149 --> 93.185.235.224

No.012  May  3 17:57:23  - [Firewall Log-PORT SCAN] TCP Packet - 107.22.70.149 --> 93.185.235.224

No.013  May  3 17:57:23  - [Firewall Log-PORT SCAN] TCP Packet - 107.22.70.149 --> 93.185.235.224

No.014  May  3 17:57:23  - [Firewall Log-PORT SCAN] TCP Packet - 107.22.70.149 --> 93.185.235.224

No.015  May  3 17:57:23  - [Firewall Log-PORT SCAN] TCP Packet - 107.22.70.149 --> 93.185.235.224

No.016  May  3 17:57:23  - [Firewall Log-PORT SCAN] TCP Packet - 107.22.70.149 --> 93.185.235.224

No.017  May  3 17:57:24  - [Firewall Log-PORT SCAN] TCP Packet - 107.22.70.149 --> 93.185.235.224

No.018  May  3 17:57:24  - [Firewall Log-PORT SCAN] TCP Packet - 107.22.70.149 --> 93.185.235.224

No.019  May  3 17:57:24  - [Firewall Log-PORT SCAN] TCP Packet - 107.22.70.149 --> 93.185.235.224

No.020  May  3 17:57:24  - [Firewall Log-PORT SCAN] TCP Packet - 107.22.70.149 --> 93.185.235.224

Best,

Nadim

1 Reply 1

jeffrrod
Level 4
Level 4

Dear Nadim,

Thank you for contacting Cisco Small Services Support Community.

Notice that the "email alert" option causes an email to be sent immediately if a DOS (Denial of Service) attack is detected that in your case is pointing to a couple IP addresses attempting to grant access your network resources and that your firewall settings denied.

Just in case it helps, I am including a link with the log settings configuration for the WRVS4400N routers;

http://sbkb.cisco.com/CiscoSB/Loginr.aspx?login=1&pid=2&app=search&vw=1&articleid=1370

Please let me know if there is any further assistance we may help you with.

Kind regards,

Jeffrey Rodriguez S.
Cisco Customer Support Engineer.

Jeffrey Rodriguez S. .:|:.:|:. Cisco Customer Support Engineer *Please rate the Post so other will know when an answer has been found.