Well, I have WAG160Nv2 and I have a 512 IDM Subscription, I configured it long ago enabling Email Alerts. Today, I was checking my email and noticed something strange, I received two emails from the modem with the Subject: Security Alert [F5:2F:0A] !! It is the first time that I receive such alerts. What surprised me is the content of the email:
Do you think that this is a normal behavior from IDM? Are they performing port scans on clients?
No.001 Sun, 2011-07-10 12:19:42 - UDP Packet - Source:193.227.177.53 Destination:10.152.x.x - [Firewall Log-PORT SCAN]
No.002 Sun, 2011-07-10 12:19:42 - UDP Packet - Source:193.227.177.53 Destination:10.152.x.x - [Firewall Log-PORT SCAN]
No.003 Sun, 2011-07-10 12:19:42 - UDP Packet - Source:193.227.177.53 Destination:10.152.x.x - [Firewall Log-PORT SCAN]
No.004 Sun, 2011-07-10 12:19:42 - UDP Packet - Source:193.227.177.53 Destination:10.152.x.x - [Firewall Log-PORT SCAN]
No.005 Sun, 2011-07-10 12:19:42 - UDP Packet - Source:193.227.177.53 Destination:10.152.x.x - [Firewall Log-PORT SCAN]
No.006 Sun, 2011-07-10 12:19:42 - UDP Packet - Source:193.227.177.53 Destination: 10.152.x.x - [Firewall Log-PORT SCAN]
No.007 Sun, 2011-07-10 12:19:42 - UDP Packet - Source:193.227.177.53 Destination: 10.152.x.x - [Firewall Log-PORT SCAN]
No.008 Sun, 2011-07-10 12:19:42 - UDP Packet - Source:193.227.177.53 Destination: 10.152.x.x - [Firewall Log-PORT SCAN]
No.009 Sun, 2011-07-10 12:19:42 - UDP Packet - Source:193.227.177.53 Destination: 10.152.x.x - [Firewall Log-PORT SCAN]
No.010 Sun, 2011-07-10 12:19:42 - UDP Packet - Source:193.227.177.53 Destination: 10.152.x.x - [Firewall Log-PORT SCAN]
The IP: 193.227.177.53 is the IP address of the DNS Server assigned by IDM (i looked it up and it is ns4.idm.net.lb) to my modem and the destination IP (I masked it) is the IP address that the modem received by DHCP from IDM.Do you think that this is a normal behavior from IDM? Are they performing port scans on clients?