This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Portscan detected from (

I received today Portscan detected from ( Has anyone seen this before? I am using google servers as dns forwarders. Thank you, Martin

This thread was automatically locked due to age.
Parents Reply
  • I've learned since then, Alex, that this also can be a DDoS attack where the sending IP is spoofed by devices on a bot net.

    Cheers - Bob

    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Thank you Alex and Bob for your input and help! I have created a "black hole" and I add to the list all portscan received. I noticed most of received portscans (90%) are coming from ec2 compute amazonaws (i.e., I understand, this is a hosted service where people create their own vm servers. Please correct if I am wrong because I also use Echo devices at home.