Hi,
I've configured destination NAT on Sophos UTM9 on public interface IP:3389->Local_ip:3389
In firewall live logging i see entries like this
Occasionally someone is sending SYN request and nothing more (this is what live log shows)
By the way netstat shows TCP Local_ip:3389 xx-xxx-33-158:54592 ESTABLISHED
and after second this ESTABLISHED is gone.
I've tried telnet from outside with one PC and established is long enough, so is this a some kind of scan?
Is this harmfull?
This thread was automatically locked due to age.