[159137] in North American Network Operators' Group
Re: Hurricane Electric Tunnelbroker staff?
daemon@ATHENA.MIT.EDU (Randy)
Sun Dec 23 17:07:09 2012
Date: Sun, 23 Dec 2012 16:06:52 -0600
From: Randy <nanog@afxr.net>
To: NANOG list <nanog@nanog.org>
In-Reply-To: <50D74458.3010106@afxr.net>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
> Hi folks,
>
> I am seeing an IPv6-connected host on my network (which is on a HE.net
> tunnel) apparently being portscanned by an HE server at
> 2001:470:0:64::2 for about the last hour or so. It is trying to hit
> several different ports four times each before moving on and
> eventually repeating itself.
>
> If anyone from HE can shed some light on what's going on here it would
> be greatly appreciated, I can provide the IP of the host in question
> off-list if needed.
>
> Thanks,
> -- Ben
Their contact is ipv6@he.net
Pretty quick response last time I contacted them.
The port scans are usually the result of the initiator of the tunnel
activating a simple security scanner. As far as I know it works only on
an address that is bound to their account.
It shouldn't be repeating itself unless there is some sort of error.