This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Portscans from ec2-54-....-12.compute-1.amazonaws.com

Hello,

I have created a "black hole" that I update with IPs received from Portscan notifications. I have done this in the last two or three years. Recently,  I noticed most of IPs are coming from compute-1.amazonaws.com, i.e.,

Source IP address: 54.92.255.12 (ec2-54-92-255-12.compute-1.amazanaws.com

I have Alexa at home. I noticed that as soon as I blacklist those IPs I receive more Portscan notifications. Then Alexa complains it has trouble to connect to Internet.

I am wondering if this is related to Alexa services. Any thoughts?

Thank you,

Martin



This thread was automatically locked due to age.
Parents
  • Update

    I had forgotten. Alexa is not connected through Sophos. My modem has two IPs (Spectrum). So, I have created two networks. One is managed by Sophos, and the other one is managed by Ubiquity. Alexa is connected to the other network.

Reply
  • Update

    I had forgotten. Alexa is not connected through Sophos. My modem has two IPs (Spectrum). So, I have created two networks. One is managed by Sophos, and the other one is managed by Ubiquity. Alexa is connected to the other network.

Children
  • Update 2

    Alexa Echo devices are not even part of any subnets managed by Sophos UTM, so my initial impression that these portscans were related to Alexa Amazon services may not be correct. However, it concerns me because more IP ranges I enter in my "black hole" then more portscans I receive from compute-1.amazanaws.com. So, I thought maybe there is a different device in my Sophos home network. There are two of them: one is Wyze camera and the one is Pumpspy. At this point, I wonder if these portscans from compute-1.amazanaws.com are just portscans or are related/needed by my devices.

    Thank you,

    Martin