Hi,
I'm looking at my event viewer system log and I
noticed a lot of errors are generated from the firewall. e.g.,
Date:
4/27/01 Event ID:
1
Time: 3:27:24
AM Source: FW1
User:
N/A Type:
Error
Computer:
A424 Category:
None
Description: FW1:,206.11.191.211
Data: Words
0000: 00000000 004c0002 00000000
c0000001
0001:0
00000000
0002:0000
The list continues for some other ips, some from
outside and some internal, and ends with the last error saying too many internal
hosts detected (307). The timespan of these errors lie within one second. I
checked the log from FW1, and noticed there is control command (ctl) issued at
that time, and no log is taken. The same errors repeats themselves in the system
log in a day. Does anyone know why this is happening? Am I being hacked?
TIA.
Norman
|