<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;Re: [Other] Linksys Incoming Log Table - What does it MEAN&#x27; in forum &#x27;Networking&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/Re-Other-Linksys-Incoming-Log-Table-What-does-it-MEAN-22654561</link>
<description></description>
<language>en</language>
<pubDate>Fri, 10 Feb 2012 14:34:11 EDT</pubDate>
<lastBuildDate>Fri, 10 Feb 2012 14:34:11 EDT</lastBuildDate>

<item>
<title>Re: [Other] Linksys Incoming Log Table - What does it MEAN</title>
<link>http://www.dslreports.com/forum/Re-Other-Linksys-Incoming-Log-Table-What-does-it-MEAN-22656844</link>
<description><![CDATA[RationalRabb posted : Thanks to both of you. You've pretty well answered my questions and quelled my fears.  :D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Other-Linksys-Incoming-Log-Table-What-does-it-MEAN-22656844</guid>
<pubDate>Sun, 05 Jul 2009 12:01:44 EDT</pubDate>
</item>

<item>
<title>Re: [Other] Linksys Incoming Log Table - What does it MEAN</title>
<link>http://www.dslreports.com/forum/Re-Other-Linksys-Incoming-Log-Table-What-does-it-MEAN-22656776</link>
<description><![CDATA[More Fiber posted : <div class="bquote"><small>said by <a href="/profile/1656153" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1656153');">RationalRabb</a>:</small><br><br>The router software allows for "Port filtering" ranges</div>Port filtering prevents undesired outbound connections.  That should only concern you if you think you might have a trojan that is opening an outbound connection (such as a spam bot).<br><div class="bquote"><small>said by <a href="/profile/1656153" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1656153');">RationalRabb</a>:</small><br><br>There are legitimate incoming IPs as well - such as my server when I access my e-mail or, I would assume, when a site sets a cookie. </div> <br>Unless you are running a server (mail, web, ftp, etc), or file sharing software (torrents), you would not normally have any inbound ports open.  When you connect to a mail server, or a web server, all requests are outbound. Most routers do <A HREF="http://en.wikipedia.org/wiki/Stateful_packet_inspection">Stateful Packet Inspection (SPI)</a> meaning they only allow an inbound response to an outbound request.  Cookies are stored by script code in the HTTP page retrieved by your browser.  They are not the result of an inbound connection.<br><br>You router is logging unsuccessful inbound connection attempts.  Since your WAN IP address is public, it can be found by any script kidde in the world that runs an IP address scan and find your IP address.<br><br>Be sure you have ICMP responses disabled in your router.  This won't prevent port scans, but will make your router less visible by not responding to pings or trace route requests.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Other-Linksys-Incoming-Log-Table-What-does-it-MEAN-22656776</guid>
<pubDate>Sun, 05 Jul 2009 11:42:59 EDT</pubDate>
</item>

<item>
<title>Re: [Other] Linksys Incoming Log Table - What does it MEAN</title>
<link>http://www.dslreports.com/forum/Re-Other-Linksys-Incoming-Log-Table-What-does-it-MEAN-22656746</link>
<description><![CDATA[tschmidt posted : <div class="bquote"><small>said by <a href="/profile/1656153" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1656153');">RationalRabb</a>:</small><br><br>There are legitimate incoming IPs as well - such as my server when I access my e-mail or, I would assume, when a site sets a cookie.  <br> </div>Not sure what you mean by "incoming IP." <br><br>When you connect to your email server (assuming you are not running one on your own network) your PC connects to port 25 (send mail) or 110 (retrieve mail) Ports 25 and 110 are called the well known ports. If server accepts connection request different ports are selected to actually exchange data, one on your PC and one on the server. Think of the well known port as a door bell, letting server know someone wants to connect.<br><br>If local PC is attempting to connect to a remote server that is an outgoing connection. If remote PC is attempting to connect to local server that is an incoming connection.<br><br>In both cases data travels in both directions. What is important is who initiates the request.<br><br>/tom]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Other-Linksys-Incoming-Log-Table-What-does-it-MEAN-22656746</guid>
<pubDate>Sun, 05 Jul 2009 11:33:43 EDT</pubDate>
</item>

<item>
<title>Re: [Other] Linksys Incoming Log Table - What does it MEAN</title>
<link>http://www.dslreports.com/forum/Re-Other-Linksys-Incoming-Log-Table-What-does-it-MEAN-22656694</link>
<description><![CDATA[RationalRabb posted : The router software allows for "Port filtering" ranges, but, as I look again, it states "Filters enable you to prevent certain PCs on your network from accessing your Internet connection", so it rather sounds like it's non-effective for what I was trying to achieve.<br><br>"That really doesn't matter because router will not forward packet so it never gets to the PC."<br><br>If you'll bear with me  :), I am still not fully understanding. Let's see if this makes sense:<br>There are legitimate incoming IPs as well - such as my server when I access my e-mail or, I would assume, when a site sets a cookie.  So I am assuming what you are telling me is that an IP address on that list is meaningless as far as someone hacking into my computer - that I should look to my firewall or other means to determine if that is actually happening.<br><br>thanks for you help, Tom]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Other-Linksys-Incoming-Log-Table-What-does-it-MEAN-22656694</guid>
<pubDate>Sun, 05 Jul 2009 11:15:46 EDT</pubDate>
</item>

<item>
<title>Re: [Other] Linksys Incoming Log Table - What does it MEAN</title>
<link>http://www.dslreports.com/forum/Re-Other-Linksys-Incoming-Log-Table-What-does-it-MEAN-22656474</link>
<description><![CDATA[tschmidt posted : <div class="bquote"><small>said by <a href="/profile/1656153" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1656153');">RationalRabb</a>:</small><br><br> I have blocked the port they most frequently seem to try to access, and the port number still appears on the list, <br> </div> <br>When you say you have blocked ports I assume you mean using PC firewall. That really doesn't matter because router will not forward packet so it never gets to the PC.<br><br>/tom]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Other-Linksys-Incoming-Log-Table-What-does-it-MEAN-22656474</guid>
<pubDate>Sun, 05 Jul 2009 10:05:24 EDT</pubDate>
</item>

<item>
<title>Re: [Other] Linksys Incoming Log Table - What does it MEAN</title>
<link>http://www.dslreports.com/forum/Re-Other-Linksys-Incoming-Log-Table-What-does-it-MEAN-22655466</link>
<description><![CDATA[RationalRabb posted : Nope - no port forwarding.<br><br>The BEFSR41 has a very simple, temporary log list. It shows an IP address and the "destination" port. I label most of the addresses as "intruders" or "potential intruders" as the IPs, which usually resolve to a standard cable ISP block, are not from areas or sites I have any interrelation with.<br><br>The reason this is critical to me is that there are entities with good reason to want to hack into my computer. Three of these addresses appear to fit other criteria to make them suspect, and these are the three that appear most frequently. So it is imperative that I understand if these denote successful access or not.<br><br>I have blocked the port they most frequently seem to try to access, and the port number still appears on the list, so I assume that, as you say, they are being dropped. But I can't afford to assume.<br><br>Thanks ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Other-Linksys-Incoming-Log-Table-What-does-it-MEAN-22655466</guid>
<pubDate>Sat, 04 Jul 2009 22:33:34 EDT</pubDate>
</item>

<item>
<title>Re: [Other] Linksys Incoming Log Table - What does it MEAN</title>
<link>http://www.dslreports.com/forum/Re-Other-Linksys-Incoming-Log-Table-What-does-it-MEAN-22655042</link>
<description><![CDATA[tschmidt posted : Unless you have enabled port forwarding, to run a server, router will drop all incoming requests. If you have enabled port forwarding the server needs to deal with the packet.<br><br>I'm curious what you mean by "actual intruder or wannabe intruders."<br><br>Once you start looking a logs you will find out there is a lot of junk floating around. Most of it is port scans, misaddressed/malformed packets and broken session.<br><br>Very old post about this type of issue:<br>&raquo;<A HREF="/shownews/28464">You pinged me you dog</A><br><br>/tom]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Other-Linksys-Incoming-Log-Table-What-does-it-MEAN-22655042</guid>
<pubDate>Sat, 04 Jul 2009 19:57:10 EDT</pubDate>
</item>

<item>
<title>Re: [Other] Linksys Incoming Log Table - What does it MEAN</title>
<link>http://www.dslreports.com/forum/Re-Other-Linksys-Incoming-Log-Table-What-does-it-MEAN-22654724</link>
<description><![CDATA[Serbtastic posted : Can you post a snippet of the log?  Edit out your own IP address but leave in those that do not belong to you.  Also include ports that were accessed.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Other-Linksys-Incoming-Log-Table-What-does-it-MEAN-22654724</guid>
<pubDate>Sat, 04 Jul 2009 18:01:22 EDT</pubDate>
</item>

<item>
<title>[Other] Linksys Incoming Log Table - What does it MEAN</title>
<link>http://www.dslreports.com/forum/Other-Linksys-Incoming-Log-Table-What-does-it-MEAN-22654561</link>
<description><![CDATA[RationalRabb posted : I have looked everywhere for this information, I cannot find a clear definition, and it is very critical to me.<br><br>My BEFSR41 Router has an Incoming Log Table that gains a new entry every few seconds, from somewhere in the world.<br><br>I do not know whether this log is indicating IP addresses of actual intruders or wannabe intruders.<br><br>Can someone with some knowledge in this area explain to me just what this list indicates?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Other-Linksys-Incoming-Log-Table-What-does-it-MEAN-22654561</guid>
<pubDate>Sat, 04 Jul 2009 17:12:11 EDT</pubDate>
</item>

</channel>
</rss>

