You are not logged in.
My server is behind a router/firewall running m0n0wall . I have a couple of non-traditional ports forwarded. I received a notice from log watch, under the sshd section, & I seem to have some unmatched entries:
--------------------- SSHD Begin ------------------------
**Unmatched Entries**
error: connect_to 184.72.234.3 port 80: failed. : 6 time(s)
I've looked up the IP and the offending host is a ec2 host from Amazon which makes me think it is malicious:
Host Name: ec2-184-72-234-3.compute-1.amazonaws.com
From the outside, I've run nmap on my network, and it reports the host is down, which makes me believe m0n0wall is doing its job.
The entry shows that the offender was trying to access port 80, which should have been dropped by m0n0wall.
My question... how is logwatch picking up these attempts when these requests for access should be dropped by the firewall?
Any insight would be greatly appreciated.
Offline