Cracking attempt

Ok, the other day someone scanned the ports from 3102 to 3230 on my
server. My firewall picked it up and told me about it. I have the
originating IP, date/time, etc...

Question: What do you suggest I do about it? I've already contacted the
owner of the IP's (cox.net) but really don't know what they will do. I was
torn between "Gee, the firewall does work" and "I'd love to catch the
sucker." Have no idea what they were looking for as services lists
Interbase and Squid in that range.



