[GH-ISSUE #923] Unknown connections on 443 #782

Closed
opened 2026-02-26 06:34:24 +03:00 by kerem · 3 comments
Owner

Originally created by @legendariusx on GitHub (Mar 4, 2021).
Original GitHub issue: https://github.com/NginxProxyManager/nginx-proxy-manager/issues/923

Hello, I'm new to using NPM and I've got a questing about my use case.
I've set up the proxy manager and forwarded ports 80 and 443.
When I checked today there were two IPs connected to port 443 idling. Might this be the result of someone port scanning? Is there any chance uf misuse by these connections?

Originally created by @legendariusx on GitHub (Mar 4, 2021). Original GitHub issue: https://github.com/NginxProxyManager/nginx-proxy-manager/issues/923 Hello, I'm new to using NPM and I've got a questing about my use case. I've set up the proxy manager and forwarded ports 80 and 443. When I checked today there were two IPs connected to port 443 idling. Might this be the result of someone port scanning? Is there any chance uf misuse by these connections?
kerem closed this issue 2026-02-26 06:34:24 +03:00
Author
Owner

@jerry110 commented on GitHub (Mar 6, 2021):

Same here

<!-- gh-comment-id:792004478 --> @jerry110 commented on GitHub (Mar 6, 2021): Same here
Author
Owner

@legendariusx commented on GitHub (Mar 8, 2021):

I tracked the connections with tcptrack and I can see that their state is SYN_SENT. I did some research and found this on Wikipedia about SYN flood. I do not get many of these connections and most of them close about 20-30 seconds after sending the SYN-Packet. So I assume these connections are malicious although they do not seem to actively do anything. Can anyone confirm?

<!-- gh-comment-id:793123801 --> @legendariusx commented on GitHub (Mar 8, 2021): I tracked the connections with tcptrack and I can see that their state is SYN_SENT. I did some research and found [this](https://en.wikipedia.org/wiki/SYN_flood) on Wikipedia about SYN flood. I do not get many of these connections and most of them close about 20-30 seconds after sending the SYN-Packet. So I assume these connections are malicious although they do not seem to actively do anything. Can anyone confirm?
Author
Owner

@legendariusx commented on GitHub (Mar 18, 2021):

I couldn't find additional information but since this isn't a problem with NPM, I'll close the issue.

<!-- gh-comment-id:801731150 --> @legendariusx commented on GitHub (Mar 18, 2021): I couldn't find additional information but since this isn't a problem with NPM, I'll close the issue.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/nginx-proxy-manager-NginxProxyManager#782
No description provided.