[159137] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Hurricane Electric Tunnelbroker staff?

daemon@ATHENA.MIT.EDU (Randy)
Sun Dec 23 17:07:09 2012

Date: Sun, 23 Dec 2012 16:06:52 -0600
From: Randy <nanog@afxr.net>
To: NANOG list <nanog@nanog.org>
In-Reply-To: <50D74458.3010106@afxr.net>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org


> Hi folks,
>
> I am seeing an IPv6-connected host on my network (which is on a HE.net 
> tunnel) apparently being portscanned by an HE server at 
> 2001:470:0:64::2 for about the last hour or so. It is trying to hit 
> several different ports four times each before moving on and 
> eventually repeating itself.
>
> If anyone from HE can shed some light on what's going on here it would 
> be greatly appreciated, I can provide the IP of the host in question 
> off-list if needed.
>
> Thanks,
> -- Ben
Their contact is ipv6@he.net
Pretty quick response last time I contacted them.
The port scans are usually the result of the initiator of the tunnel 
activating a simple security scanner. As far as I know it works only on 
an address that is bound to their account.
It shouldn't be repeating itself unless there is some sort of error.




home help back first fref pref prev next nref lref last post