[66141] in North American Network Operators' Group
Re: Stopping ip range scans
daemon@ATHENA.MIT.EDU (haesu@towardex.com)
Mon Dec 29 08:49:03 2003
Date: Mon, 29 Dec 2003 08:48:25 -0500
From: haesu@towardex.com
To: william@elan.net
Cc: Abdullah Hameed Sheikh <ahameed@singtel.com>, nanog@nanog.org
In-Reply-To: <Pine.LNX.4.44.0312290429120.21468-100000@sokol.elan.net>
Errors-To: owner-nanog-outgoing@merit.edu
[.. SNIP ..]
> The problem is these are random scans, the traffic is going to ips that
> are not used and never were. They're clearly a random sequential scans.
In this particular case, null-routing your aggregate is your friend. Or get a
sink hole and suck down all the !traffic to it. Please, it's the internet. Port
scans are nothing out of the ordinary.
-James
--
James Jun (formerly Haesu)
TowardEX Technologies, Inc.
1740 Massachusetts Ave.
Boxborough, MA 01719
Consulting, IPv4 & IPv6 colocation, web hosting, network design & implementation
http://www.towardex.com | james@towardex.com
Cell: (978)394-2867 | Office: (978)263-3399 Ext. 170
Fax: (978)263-0033 | AIM: GigabitEthernet0
NOC: http://www.twdx.net | POC: HAESU-ARIN, HDJ1-6BONE