win xp sp1 changes ICF settings/rules and/or default behavior for snmp packet processing on udp 162?

From: Ken.Williams@ey.com
Date: 09/18/02


To: focus-ms@securityfocus.com
From: Ken.Williams@ey.com
Date: Wed, 18 Sep 2002 12:22:42 -0500

i have a box running win xp pro, on a lan connected to a linksys
router. i use linklogger to snag the logs being broadcast by
the linksys to udp 162. before installing xp sp1, i had no
problems with this setup, and i didn't have to make any changes
to ICF, which was enabled on the xp box. after installing xp
sp1, all snmp packets broadcasted to udp 162 were dropped by the
xp box. i don't have time to investigate further, but i suspect
that sp1 changes ICF settings or defaults, or some other facet
of SNMP. the solution was to add a new "service" [read: rule]
to ICF called "snmp" that permitted network to access "snmp" via
udp port 162 (internally and externally). anybody else noticed
this, or had the time to get to the bottom of the situation and
determine exactly what changes xp sp1 makes to ICF and/or SNMP?

thanks,
ken

Ken Williams, CISSP

________________________________________________________________________
The information contained in this message may be privileged and confidential and protected from disclosure. If the reader of this message is not the intended recipient, or an employee or agent responsible for delivering this message to the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this communication in error, please notify us immediately by replying to the message and deleting it from your computer. Thank you. Ernst & Young LLP



Relevant Pages

  • RE: win xp sp1 changes ICF settings/rules and/or default behavior for snmp packet processing on udp
    ... I have noticed that with XP SP1 and ICF turned off, ... still drops UDP packets sent from my exchange server to tell outlook ... I have no idea why it does this but suspect ICF ... all snmp packets broadcasted to udp 162 were dropped by the ...
    (Focus-Microsoft)
  • Re: [Full-Disclosure] SNMP Broadcasts
    ... Most older "default" SNMP devices broadcast traps. ... can just be placed on the network and managed without any special ...
    (Full-Disclosure)
  • Re: SNMP Fails on Windows 2003 Server (std) DC
    ... my servers after installing SP1. ... I have 7 servers total and it only ... >All are recently setup with SP1 and all have SNMP installed and configured. ...
    (microsoft.public.windows.server.networking)
  • Re: [Full-Disclosure] SNMP Broadcasts (fwd)
    ... > specified SNMP community. ... > can just be placed on the network and managed without any special ... > broadcast packets to all hosts on the subnetwork. ... This is a variant, and interestingly, that port is assigned to ...
    (Full-Disclosure)
  • Broadcasting an SNMP GET - idSNMP?
    ... I need to broadcast an SNMP GET request onto the local subnet, ... The idSNMP component has a BroadcastEnabled property, and I can send the GET ...
    (alt.comp.lang.borland-delphi)