LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Non-*NIX Forums > General
User Name
Password
General This forum is for non-technical general discussion which can include both Linux and non-Linux topics. Have fun!

Notices


Reply
  Search this Thread
Old 06-19-2016, 09:43 AM   #1
trafikpolisen
Member
 
Registered: Jun 2008
Posts: 121

Rep: Reputation: 3
My firewall gets hammered with traffic to port 443 after switching ISP, what's going on?


Hi! I very recently switched from a Telia DSL connection to a small ISP via a local fiber network. Now, after switching ISP, my firewall blocks a lot of incoming traffic to port 443. I don't run any web server or anything, and when I checked a few random source addresses, they're all originating from China. Any ideas what's happening?
 
Old 06-19-2016, 10:11 AM   #2
maples
Member
 
Registered: Oct 2013
Location: IN, USA
Distribution: Arch, Debian Jessie
Posts: 814

Rep: Reputation: 265Reputation: 265Reputation: 265
Sounds like you drew a short straw. Some Chinese guys have your IP address and they think that something's there. If you've got a dynamic IP, the last person to have your address probably had something they were interested in.

I'd unplug your router/modem for a while to try to get a new IP. Don't know how long it will take. I'd start by leaving it off overnight, but it might take longer. Some routers give information about when their DHCP lease expires; I'd make sure that it's off when that happens so it can't renew it.

You might also try contacting your ISP and tell them what's going on, but I don't know what they will be able to do about it.
 
Old 06-19-2016, 10:30 AM   #3
af7567
Member
 
Registered: Nov 2012
Posts: 293

Rep: Reputation: 106Reputation: 106
Quote:
Originally Posted by trafikpolisen View Post
Hi! I very recently switched from a Telia DSL connection to a small ISP via a local fiber network.
It is possible that you have always had these incoming connections but you never noticed because your DSL router (or maybe your ISP) was blocking them for you. People are always scanning random IP addresses hoping to find unpatched security holes - I get loads of connections from China too on www and ssh ports. There isn't anything you can do to stop it, just make sure you don't have any services running that don't need to be and make sure your firewall is turned on.

If your fibre modem is connected directly to your PC then your PC will have a public IP address which is why all connections are making it to the PC. To stop that you could get a separate firewall which plugs in between the fibre modem and your local network (which may be similar to how your DSL was set up).
 
Old 06-19-2016, 11:18 AM   #4
trafikpolisen
Member
 
Registered: Jun 2008
Posts: 121

Original Poster
Rep: Reputation: 3
Quote:
Originally Posted by maples View Post
Sounds like you drew a short straw. Some Chinese guys have your IP address and they think that something's there. If you've got a dynamic IP, the last person to have your address probably had something they were interested in.

I'd unplug your router/modem for a while to try to get a new IP. Don't know how long it will take. I'd start by leaving it off overnight, but it might take longer. Some routers give information about when their DHCP lease expires; I'd make sure that it's off when that happens so it can't renew it.

You might also try contacting your ISP and tell them what's going on, but I don't know what they will be able to do about it.
Thanks, I'll try that!

Quote:
Originally Posted by af7567 View Post
It is possible that you have always had these incoming connections but you never noticed because your DSL router (or maybe your ISP) was blocking them for you. People are always scanning random IP addresses hoping to find unpatched security holes - I get loads of connections from China too on www and ssh ports. There isn't anything you can do to stop it, just make sure you don't have any services running that don't need to be and make sure your firewall is turned on.

If your fibre modem is connected directly to your PC then your PC will have a public IP address which is why all connections are making it to the PC. To stop that you could get a separate firewall which plugs in between the fibre modem and your local network (which may be similar to how your DSL was set up).
My DSL connection is still active, so I connected my router to that again and checked, but it's only with my new connection I get that specific traffic from China to port 443. On my DSL connection the blocked incoming traffic is more "random", so I think maples might be right.

On my old connection my DSL modem just acts as a modem and my MikroTik router gets a public IP. With the new I just connect my router to an ethernet jack in my apartment and my router gets a public IP.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
n00b Question: use router to direct port 80 and 443 traffic to separate proxy server? DurocShark Linux - Newbie 9 11-19-2009 06:29 AM
routing traffic for multiple web servers through one port (443 preferably) miedward Linux - Software 3 05-04-2009 02:21 AM
How to block ALL traffic except port 443 carlozrox Linux - Security 2 03-11-2009 05:15 AM
ISP blocked port 80,443,563...now what? andrew_cz Linux - Networking 4 07-08-2006 04:54 PM
How do I know if it is my iSP blocking port 25 or my RH8 Firewall setting lho Linux - Networking 10 04-11-2003 12:14 PM

LinuxQuestions.org > Forums > Non-*NIX Forums > General

All times are GMT -5. The time now is 12:03 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration