[66141] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Stopping ip range scans

daemon@ATHENA.MIT.EDU (haesu@towardex.com)
Mon Dec 29 08:49:03 2003

Date: Mon, 29 Dec 2003 08:48:25 -0500
From: haesu@towardex.com
To: william@elan.net
Cc: Abdullah Hameed Sheikh <ahameed@singtel.com>, nanog@nanog.org
In-Reply-To: <Pine.LNX.4.44.0312290429120.21468-100000@sokol.elan.net>
Errors-To: owner-nanog-outgoing@merit.edu


[.. SNIP ..]

> The problem is these are random scans, the traffic is going to ips that 
> are not used and never were. They're clearly a random sequential scans.

In this particular case, null-routing your aggregate is your friend. Or get a
sink hole and suck down all the !traffic to it. Please, it's the internet. Port
scans are nothing out of the ordinary.

-James


-- 
James Jun (formerly Haesu)
TowardEX Technologies, Inc.
1740 Massachusetts Ave.
Boxborough, MA 01719
Consulting, IPv4 & IPv6 colocation, web hosting, network design & implementation
http://www.towardex.com  | james@towardex.com
Cell: (978)394-2867      | Office: (978)263-3399 Ext. 170
Fax: (978)263-0033       | AIM: GigabitEthernet0
NOC: http://www.twdx.net | POC: HAESU-ARIN, HDJ1-6BONE

home help back first fref pref prev next nref lref last post