How server got attacked from outside of NAT?

03/10/2005 05:19:34 Active Response Disengaged Information None None 64.233.189.104 00-00-00-00-00-00 0.0.0.0 00-00-00-00-00-00 Administrator NSA Normal 1 03/10/2005 05:19:34 03/10/2005 05:19:34
03/10/2005 05:56:59 Port Scan Minor Incoming TCP 199.232.148.234 00-11-95-71-19-1C 192.168.0.100 00-04-23-52-EF-B5 Administrator NSA Normal 1 03/10/2005 05:56:59 03/10/2005 05:56:59

I just could not understand how could a Port Scan is seen on an internal IP address, when the attack is from outside?

Am I missing some bigger problem here? Did I have a leak on firewall, or the machine is already hacked?

 

 

 

 

Top