Hi, since some weeks I find these entries in my /var/log/warn: scanlogd: From 127.0.0.1 to 127.0.0.1 ports 4228, 4230, 4232, 4234, 4236, 4238, 4240, 4242, 4244, ..., flags f?rp?u, TOS 00, TTL 64, started at 08:09:22 They appear not daily. But every third or fourth day. It seems that my linux box does a portscan on its own !? I am running Suse 6.2 (Kernel 2.2.10) with sendmail, squid, apache (default versions from Suse 6.2) and Samba 2.07. This box is now running over 18 month without any problems. After this portscan the proxy cancel the download of web pages during the loading. After hitting "reload" in the browser the page gets loaded - sometimes not. A restart of the proxy doesn't solve the problem. When I copy a 50MB file via samba on this computer this works well. I think not that this is a problem with the network card (it is a 3com). Does anybody knows whats going on here ? Thanks for your help Thorsten -- Newell Window Fashions Germany GmbH EDV / Dept. IT Neutrauchburger Str. 20 D-88316 Isny Thorsten Schneider Tel.: (+49) 7562 / 985-112 Fax: - 100 t.schneider@newellwf-de.com www.newellwf-de.com