Probably no big deal although I have questions. Background: My home wireless was being overrun with all the devices. Have 6 people on the net and each have multiple devices. Then the kids would have friends over and the device count would go up. I have identified the mac addys for the local devices and modified iptables and dhcp to redirect unknown devices to a specific web page and not allow them on the network.
So for the problem. During my watching of the network I have found that Amazon, Xbox and some Androids ping multiple different ports on my router. Most ports are above 1024, although I have seen some below that. Pings happen about every minute and a half per device. Some ping 10 times, other less. Every once in awhile we get more than 10 pings; all are using different destination ports. Some pings are from the source out in inet land with most being from the local device. Sure, ping uses a tiny amount of bandwidth.
So my question: Anybody have any idea of what are these pings for? Looking at it as a security issue, it sure could be a 'slow' port scan to find holes in my systems. Since these devices are smart devices, just about anything could be done given a flaw in my network if there is one. I have dropped them at the router using the INPUT and FORWARD chains unless somebody gives me a good reason not to.
Maybe I am thinking all wrong about this - ideas?
Thanks
Todh
Welp, made an executive decision. Decided to drop all of the above packets and see who here complained. So far nobody! In other words, I gave up and just dropping stuff was easier.
Asked by ctclibby
(29 rep)
Mar 30, 2020, 10:21 AM
Last activity: Apr 4, 2020, 01:22 PM
Last activity: Apr 4, 2020, 01:22 PM