Hurricane Electric Tunnelbroker staff?
nanog at afxr.net
Sun Dec 23 22:06:52 UTC 2012
> Hi folks,
> I am seeing an IPv6-connected host on my network (which is on a HE.net
> tunnel) apparently being portscanned by an HE server at
> 2001:470:0:64::2 for about the last hour or so. It is trying to hit
> several different ports four times each before moving on and
> eventually repeating itself.
> If anyone from HE can shed some light on what's going on here it would
> be greatly appreciated, I can provide the IP of the host in question
> off-list if needed.
> -- Ben
Their contact is ipv6 at he.net
Pretty quick response last time I contacted them.
The port scans are usually the result of the initiator of the tunnel
activating a simple security scanner. As far as I know it works only on
an address that is bound to their account.
It shouldn't be repeating itself unless there is some sort of error.
More information about the NANOG