port scan from DSL-2750B hsi router every 5 minutes
petermcmorran
Enthusiast - Level 1

I'm new to Verizon hsi and I've noticed that the D-link DSL-2760B router attempts a port scan every 5 minutes or so. These are reported and blocked by my SystemSuite 7 firewall, but this causes a temporary block of all transfers from the router IP address 192.168.1.1, resulting in transient server not found, etc. errors. This is over a wireless connection between the desktop computer and the router. Are these port scans actually originating from the router, or are they from outside IP's being forwarded for the local net? Should I allow random connections from the router? How can they be stopped?

Just noticed that, after 8 attempts, it's now been quiet for 15 minutes. So maybe it is just a naughty outside user. Hmmm...

Everything else is working smoothly with the wireless connection and internet service.

Thanks,

{edited for privacy}

0 Likes
1 Solution

Correct answers
Re: port scan from DSL-2750B hsi router every 5 minutes
petermcmorran
Enthusiast - Level 1

Believe this may solve the problem. These are not actually port scans, but DNS replies. The System Suite Net Defense firewall is confused by DNS replies appearing to come from the router. You need to create advanced rules to allow both TCP and UDP connections from the router IP address originating from the DNS server port, 53, to any port on the computer. Be sure to make the rules ALLOW; my first attempt was to block, resulting in no DNS at all.

HTH,

Peter

View solution in original post

0 Likes
Re: port scan from DSL-2750B hsi router every 5 minutes
petermcmorran
Enthusiast - Level 1

Believe this may solve the problem. These are not actually port scans, but DNS replies. The System Suite Net Defense firewall is confused by DNS replies appearing to come from the router. You need to create advanced rules to allow both TCP and UDP connections from the router IP address originating from the DNS server port, 53, to any port on the computer. Be sure to make the rules ALLOW; my first attempt was to block, resulting in no DNS at all.

HTH,

Peter

0 Likes