Seems like you have Post Scan detection enabled in SmartDefense.
Cheers,
Kerem
> -----Original Message-----
> From: Mailing list for discussion of Firewall-1 [mailto:FW-1-
> MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM] On Behalf Of Tom Brown
> Sent: Monday, November 28, 2005 3:00 PM
> To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
> Subject: [FW-1] AI R55 - SPLAT - Squid Proxy - Port Scanning
>
> Hi
>
> just deployed a squid proxy in front of one our web servers in the IDC
> and now when we hit the site in question behind the proxy our firewall
> in the office thinks its being port scanned by the squid host -
>
> Does anyone know why that might be?
>
> thanks
>
> =================================================
> To set vacation, Out-Of-Office, or away messages,
> send an email to LISTSERV AT amadeus.us.checkpoint DOT com
> in the BODY of the email add:
> set fw-1-mailinglist nomail
> =================================================
> To unsubscribe from this mailing list,
> please see the instructions at
> http://www.checkpoint.com/services/mailing.html
> =================================================
> If you have any questions on how to change your
> subscription options, email
> fw-1-owner AT ts.checkpoint DOT com
> =================================================
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================
|