- Dec 6, 2023
- 895
Any further measures needed?It means Symantec Endpoint Protection (SEP) is detecting and blocking attempts by external IP addresses to identify open ports in your system - a common precursor to cyber attacks. It's a sign that SEP is doing its job protecting your network.
While SEP is effectively blocking these attempts, it's always a good idea to ensure your software is up to date, enforce strong password policies, and educate users about phishing scams. Regularly monitor your logs to identify any persistent or suspicious activity.Any further measures needed?
Do you have any torrent application running while getting these alerts? Or any other pc in your lan has torrent application running ?Any further measures needed?
No; I do not use torrent at all.Do you have any torrent application running while getting these alerts? Or any other pc in your lan has torrent application running ?
You have the IP address check it and look where the traffic is coming fromModem router is connected only to my PC and another turned off one by cable.
Check whether your router has firewall functionality? If so check whether it's properly configured or not. Do you have static IP address or dynamic ip address from your isp? If you have a dynamic ip address, your isp would be shielding your ports from their side. You can test it's integrity by going to GRC | ShieldsUP! — Internet Vulnerability Profiling. You can also consider a hardware firewall like opnsense or pfsense, mikrotik hap ac3 etc for added protection.No; I do not use torrent at all.
Modem router is connected only to my PC and another turned off one by cable.
How can I check such IP addresses?You have the IP address check it and look where the traffic is coming from
Maybe it's malicious maybe not but usually software shouldn't scan for active ports if default ones are open
So it is suspicious but not necessarily malicious
My modem router firewall is set to max.Check whether your router has firewall functionality? If so check whether it's properly configured or not. Do you have static IP address or dynamic ip address from your isp? If you have a dynamic ip address, your isp would be shielding your ports from their side. You can test it's integrity by going to GRC | ShieldsUP! — Internet Vulnerability Profiling. You can also consider a hardware firewall like opnsense or pfsense, mikrotik hap ac3 etc for added protection.
These port scans are not that concerning, it happens all the time. You can switch off your router for some time and restart it so that your isp might issue a new dynamic ip address, with that the port scanning may go away for some time.I keep getting more and more logs of port scanning from several IP addresses.
Any way to block trials of port scanning?These port scans are not that concerning, it happens all the time. You can switch off your router for some time and restart it so that your isp might issue a new dynamic ip address, with that the port scanning may go away for some time.
As I said, it's not that dangerous per se as your software firewall blocks it. If you are that concerned get a good hardware firewall.Any way to block trials of port scanning?
I am not concerned; I am aksing you if I shouldAs I said, it's not that dangerous per se as your software firewall blocks it. If you are that concerned get a good hardware firewall.
I am not concerned; I am aksing you if I should![]()
Instructions to allow traffic from IP addresses if deemed safe; but if not safe, what should be performed?Handling Port Scan Detections in Symantec Endpoint Protection 14.x
knowledge.broadcom.com