One of our mail servers sits behind a firewall.
Yesterday we had a possible hack incident, so I've been checking through our firewall log.
It shows a port scan from the proxmox to our mail server. [see below]
09/19/2008 09:32:49.176 Alert Intrusion Prevention Possible port scan detected PROXMOXIPADDRESS, 34820, WAN FIREWALLADDRESS, 17641, WAN TCP scanned port list, 17612, 17605, 17592, 17630, 17635
This showed up a number of times yesterday also. Does anyone know why this might be?
Yesterday we had a possible hack incident, so I've been checking through our firewall log.
It shows a port scan from the proxmox to our mail server. [see below]
09/19/2008 09:32:49.176 Alert Intrusion Prevention Possible port scan detected PROXMOXIPADDRESS, 34820, WAN FIREWALLADDRESS, 17641, WAN TCP scanned port list, 17612, 17605, 17592, 17630, 17635
This showed up a number of times yesterday also. Does anyone know why this might be?