[LUNI] Re: Cablemodem Discussion (Was: DHCP host name - COMCAST - cable modem)

Sushi Technologies sushitech at voxlox.com
Mon Jun 30 09:46:13 CDT 2003


Hmm!  This IS interesting.
I have a Netscreen 5XT firewall at home and have implemented a pretty robust ruleset, and something very like this keeps showing up in my "packets dropped to self" log.  The IP in question has a different DNS name these days, but what *I* see happening is that the cable modem itself keeps attempting to contact this address via "IP PROTOCOL 2".  

Nothing seems to be harmed by my blocking it, so I'll continue to do so.

The only other scans I see are the occasional attempt from a Comcast IP to connect to my (nonexistent) web server on port 80. ;)

-- Derek W.
  This brings up another interesting point -- back when home.com was around, there was an address that would pop up from time-to-time.  It resolved to:  "AUTHORIZED-SCAN1.home.com" and was something like 24.0.0.100 or some real low IP 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://luni.org/pipermail/luni/attachments/20030630/b7ff2a23/attachment.html 


More information about the luni mailing list