[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [FW-1] TCP port ddt_1052 nimireg_1059
Dear all, Looking at the firewall checkpoint log nearly a week, I have been constantly seeing many failing attempts from an internal PC with the above services I still don't know the IP address of the internal PC as the firewall logs shows the Proxy Server is actually source and Firewall the target destination. I have also run "netstat -a" from Proxy Server many times, don't seem to see those port 1052 & 1059 are running at all. Scenario 1 ========== An INTERNAL PC --> Proxy Server --> Firewall with services port 1052 DROP Scenario 2 ========== An INTERNAL PC --> Proxy Server --> Firewall with services port 1059 DROP I have been told ddt_1052 is dynamic dns tool. I don't think Proxy run this service locally. Is this then run by a user who is doing some naughty work? I don't know what both services are doing really. Your tips would be much appreciated. I am a new learner about security & network packets. Have you seen this before? Where to from here really? Thanks muchly. BY ================================================= To set vacation, Out Of Office, or away messages, send an email to [email protected] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [email protected] =================================================
|