Constant Malicious Port Scanning: Intrusion Prevention

Constant Malicious Port Scanning: Intrusion Prevention

Constant Malicious Port Scanning: Intrusion Prevention
Constant Malicious Port Scanning: Intrusion Prevention
Friday - last edited Yesterday
Tags: #home shield
Model: Deco XE75  
Hardware Version: V1
Firmware Version: 1.4.1

I've had this XE75 about three weeks (replaced 4 node M5) and have actived Home Shield

Over the last 48 hours I've been getting increasing Intrusion Prevention Messages and Warnings.

I have had 9 warnings today alone from my network security "Home Shield has prevented a malicious attack.  Malicious port Scanning detected.  I click the warning and It shows that the source MAC is a device on the network and the source IP is the address of the same device.  The target IP I can't find on my network.

 

* Source MAC = ROON ROCK MAC
* Source IP = ROON ROCK IP
* Target IP = IP Address of a device I cannot find on my network.

 

I'm a music lover, entrepreneur and pastor not a network engineer.   If this is an external attack why is the source MAC and IP from an internal device?  Can someone tell me what this means and how to stop it.    "Home Shield" keeps blocking it but frequency is increasing.    I tried Isolating the device ROON ROCK (it's a music server)  but of course then none of my controllers could run the sy

Anyway, any insight as to what's going on would be appreciated
 

  1      
  1      
#1
Options
1 Accepted Solution
Re:Constant Malicious Port Scanning: Intrusion Prevention-Solution
Monday - last edited Yesterday

  @David-TP 

I'm trying to upload the screenshots of the attacking records but I continue to get error messages that Source URL is missing.  I think I figured out what is / was going on.  My ROON ROCK music server has been scanning the network looking for new endpoints and music files to consolidate my library.  I made an Intrusion Exception for that device and it has stopped and music playback has been far more stable..   I'll upload the logs now

File:
Screenshot_2025-11-02-18-41-31-69_f49179b090611efe64122144cd8cb960.jpgDownload
Recommended Solution
  1  
  1  
#3
Options
4 Reply
Re:Constant Malicious Port Scanning: Intrusion Prevention
Monday

  @holsen1 

Hi, thank you very much for your feedback.

Could you please refer to this link to help me submit the Deco App log:How to submit Deco APP log

Please also add a screenshot of the attacking records under HomeShield>Security.

 

Thanks a lot.

Wait for your reply.

Best regards.

 

  0  
  0  
#2
Options
Re:Constant Malicious Port Scanning: Intrusion Prevention-Solution
Monday - last edited Yesterday

  @David-TP 

I'm trying to upload the screenshots of the attacking records but I continue to get error messages that Source URL is missing.  I think I figured out what is / was going on.  My ROON ROCK music server has been scanning the network looking for new endpoints and music files to consolidate my library.  I made an Intrusion Exception for that device and it has stopped and music playback has been far more stable..   I'll upload the logs now

File:
Screenshot_2025-11-02-18-41-31-69_f49179b090611efe64122144cd8cb960.jpgDownload
Recommended Solution
  1  
  1  
#3
Options
Re:Constant Malicious Port Scanning: Intrusion Prevention
Yesterday

  @holsen1 

Hi, thank you very much for the logs.
I also found a similar post:https://community.roonlabs.com/t/constant-scanning-of-library-how-do-i-stop-it/292308/9.

In this way, I think HomeShield Security did correctly detect Malware-like activities.

Thanks a lot.

Best regards.
 

  0  
  0  
#4
Options
Re:Constant Malicious Port Scanning: Intrusion Prevention
Yesterday
Thanks for that. I read that entire thread. It could be that there are or may be a corrupt file that prevent roon from complete ting the library scan, but then roon does show me what the corrupt file are so I can remove them. I will send my logs over to ROON Labs to take a look. That thread concludes that a product that rhymes with Halware Rytes was incorrectly seeing Roon as a malicious attack, which is what I'm inclined to believe here, that Homeshield is incorrectly seeing Roon as a Malicious Attack. Anyway, for now, I have made an Exception for the Roon server in the intrusion prevention and if Roon Labs can identify a corrupted file(s), I'll remove it / the amd then remove the exception to see what happens. For now, I'm pretty convinced my Roon DB is clean and that homeshield is giving a false positive. I'll come back if there's any further update.
  0  
  0  
#5
Options