<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewall Log Entry in Security</title>
    <link>https://community.talktalk.co.uk/t5/Security/Firewall-Log-Entry/m-p/3017662#M23627</link>
    <description>&lt;P&gt;I have a Huawei DG8041W b/band router which to be fair has been well behaved and reliable over the 4yrs or so since installation. I was looking through the various menus and found the following in the Firewall log which looked a bit weird to me as the src IP resolves to Kazakstan!!. The dest IP seems to be within the TalkTalk range though not mine now - though guess there's dynamic allocation so may have been back in June 2020. I've had the router since April 2020&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;2020-06-05 12:26:56 [Notice] IN=ppp257 OUT=LocalNetwork Direction=Public-&amp;gt;Private Action=Permit src=185.176.27.30 DST=79.76.80.166 PROTO=TCP SPT=51681 DPT=17281&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Questions are: a) am i paranoid or is this weird? b) how can i check if this route is still enabled (I have nmap'd myself and neither port is open though guess they mightn't be).&lt;/P&gt;&lt;P&gt;I work in IT though mainly management these days so some of my skills have waned though still understand (most of) the theory so people don't need to dumb down any responses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Jan 2024 21:16:47 GMT</pubDate>
    <dc:creator>CotswoldColin</dc:creator>
    <dc:date>2024-01-23T21:16:47Z</dc:date>
    <item>
      <title>Firewall Log Entry</title>
      <link>https://community.talktalk.co.uk/t5/Security/Firewall-Log-Entry/m-p/3017662#M23627</link>
      <description>&lt;P&gt;I have a Huawei DG8041W b/band router which to be fair has been well behaved and reliable over the 4yrs or so since installation. I was looking through the various menus and found the following in the Firewall log which looked a bit weird to me as the src IP resolves to Kazakstan!!. The dest IP seems to be within the TalkTalk range though not mine now - though guess there's dynamic allocation so may have been back in June 2020. I've had the router since April 2020&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;2020-06-05 12:26:56 [Notice] IN=ppp257 OUT=LocalNetwork Direction=Public-&amp;gt;Private Action=Permit src=185.176.27.30 DST=79.76.80.166 PROTO=TCP SPT=51681 DPT=17281&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Questions are: a) am i paranoid or is this weird? b) how can i check if this route is still enabled (I have nmap'd myself and neither port is open though guess they mightn't be).&lt;/P&gt;&lt;P&gt;I work in IT though mainly management these days so some of my skills have waned though still understand (most of) the theory so people don't need to dumb down any responses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 21:16:47 GMT</pubDate>
      <guid>https://community.talktalk.co.uk/t5/Security/Firewall-Log-Entry/m-p/3017662#M23627</guid>
      <dc:creator>CotswoldColin</dc:creator>
      <dc:date>2024-01-23T21:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Log Entry</title>
      <link>https://community.talktalk.co.uk/t5/Security/Firewall-Log-Entry/m-p/3017666#M23628</link>
      <description>&lt;P&gt;Do you have anything on any of your devices that are using TCP port&amp;nbsp;17281? Is UPnP enabled on your DG8041W, this may be a temp port forwarding rule that has been added by UPnP, if enabled.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 21:54:54 GMT</pubDate>
      <guid>https://community.talktalk.co.uk/t5/Security/Firewall-Log-Entry/m-p/3017666#M23628</guid>
      <dc:creator>KeithFrench</dc:creator>
      <dc:date>2024-01-23T21:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Log Entry</title>
      <link>https://community.talktalk.co.uk/t5/Security/Firewall-Log-Entry/m-p/3017671#M23629</link>
      <description>&lt;P&gt;hi, thanks for replying so quick. Yes good point, I did buy a cheapy (Sannce) CCTV system which includes an internet connected DVR which I (think) I setup during the initial lockdown period so could well tally with the June '20 date. I created a separate VLAN on the router to segment it from the rest of my home network as not sure I trust it given what you read on the net about such things. I did setup remote monitoring of the CCTV from my smartphone so guess the DVR/control unit 'punched' out to the net to setup the firewall rule though I'd have thought other devices over the years would have done similar though that's the only line in log? I will do some investigations and setup the DVR back on the wifi to see if another rule is created now that I'm on different&amp;nbsp; IP as it's been offline for a while&lt;/P&gt;&lt;P&gt;Thanks again,&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 22:03:57 GMT</pubDate>
      <guid>https://community.talktalk.co.uk/t5/Security/Firewall-Log-Entry/m-p/3017671#M23629</guid>
      <dc:creator>CotswoldColin</dc:creator>
      <dc:date>2024-01-23T22:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Log Entry</title>
      <link>https://community.talktalk.co.uk/t5/Security/Firewall-Log-Entry/m-p/3017672#M23630</link>
      <description>&lt;P&gt;I would disable UPnP anyway as it is highly insecure &amp;amp; stick with port forwarding. However, if that was the last entry back in June 2020, I would think that there is nothing to worry about.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 22:17:30 GMT</pubDate>
      <guid>https://community.talktalk.co.uk/t5/Security/Firewall-Log-Entry/m-p/3017672#M23630</guid>
      <dc:creator>KeithFrench</dc:creator>
      <dc:date>2024-01-23T22:17:30Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Log Entry</title>
      <link>https://community.talktalk.co.uk/t5/Security/Firewall-Log-Entry/m-p/3017913#M23636</link>
      <description>&lt;P&gt;Hi Again,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Thanks for the advice. It sounds like a prudent step to implement.&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2024 19:53:34 GMT</pubDate>
      <guid>https://community.talktalk.co.uk/t5/Security/Firewall-Log-Entry/m-p/3017913#M23636</guid>
      <dc:creator>CotswoldColin</dc:creator>
      <dc:date>2024-01-24T19:53:34Z</dc:date>
    </item>
  </channel>
</rss>

