What's new

Help with these odd 192 IP's showing up in my netscan

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

compudoc

New Around Here
Hey guys thanks in advance for your help with this question, not sure if i am looking at some bad activity or just what?

When I use Angry IP scanner on this office's network that I am installing some new PC's and perform a scan in its random mode setting (looking at different addresses in the 192 sub-net i think?) I am seeing some VERY weird replies from boxes not on this network but what appears systems that could or maybe are able to access this "private" subnet - I have attached a few of the random scans for your viewing pleasure and hope to get your opinions on WTF this is
 

Attachments

  • random scan 1  8-25-14.JPG
    random scan 1 8-25-14.JPG
    21 KB · Views: 296
  • random scan 2 8-25-14.JPG
    random scan 2 8-25-14.JPG
    27.8 KB · Views: 492
Sorry forgot to give better details - Network provider = ATT with 381HGV / Asus RT-AC66U

Asus RT-AC66U router is behind the ATT U-Verse 381HGV Modem/router that I have it set to pass all ports (setting at the bottom of the ATT advance firewall settings page) to the MAC address of the Asus router.

The 381 is plugged into the Asus WAN port with all clients connected to the wired ports on the AC66
 
You have a lot of class B networks showing up. What is your network scope? This is probably defined on your DHCP server. What do the different colors means on the random scans? Are you scanning beyond your network? Check your network scope in the scanning software.
 
Last edited:
RMerlin firmware has configurable firewall, other than that cisco, juniper, mikrotik and pfsense have them too. Its not professional to use a consumer router in an office environment. How can you not know what ip address your network is using? You should already know your network architecture, layout and configurations. I specifically remember all these manufacturers claiming their products for homes/SOHO not SMEs.

Using RMerlin's firmware you create a bunch of rules to drop forwarding at scr-nat from class B and below IPs that are not your network.
 

Similar threads

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top