Re: Never seen this before?

From: Derek Nash (derek@nashworld.net)
Date: 09/06/02


From: "Derek Nash" <derek@nashworld.net>
Date: Fri, 6 Sep 2002 14:18:48 -0500

UDP port 500 is Internet Key Exchange (IKE) protocol which is most commonly
seen in the setup of a VPN connection. If you are running some VPN software
or using the Windows VPN connection you would see traffic like this. It
could also be a new undocumented exploit. :)

"-lone_wolf-" <-lone_wolf-@NO_SPAMexcite.com> wrote in message
news:I96e9.275803$f05.14724360@news1.calgary.shaw.ca...
> Would someone be able to explain what this message was on my firewall
> (in layman's terms?)
>
> TIME: 09/06/2002 10:54:46
> ACTION: Blocked
> PROTOCOL: UDP
> DIRECTION: Incoming
> DESTINATION HOST: 24.76.248.XXX
> DESTINATION PORT: 500
> SOURCE IP: 24.76.169.XXX
> SOURCE PORT: 500
> APPLICATION INVOLVED: C:\WINDOWS\system32\lsass.exe
> COUNT: 1
> BEGIN TIME: 09/06/2002 10:54:11
> END TIME: 09/06/2002 10:54:11
> RULE NAME:
> GUI%GUICONFIG#SRULE@APPCONFIG-TCP#C:\WINDOWS\System32\LSASS.EXE
>
> Thanks in advance
>
> John
>
>



Relevant Pages

  • RE: SBS2K3 Prem Symantec Security Gaeway
    ... locate the Protocol Definitions container. ... In the Port number box, ... UDP port 49152 Receive/Send, ...
    (microsoft.public.windows.server.sbs)
  • Re: Fairly Urgent regarding the CSocket Class (Arent they all)
    ... Running in the IDE it would hang at the .Bind call on the UDP port after ... setting the protocol and port number. ...
    (microsoft.public.vb.general.discussion)
  • Re: Virtualized VPN
    ... If you want to port forward PPTP VPN traffic, you need to forward TCP 1723 as well as GRE or Protocol ID 47. ... Theres's two parts of it, the L2TP traffic uses UDP Port 1701, and the IPSec traffic requires the following: UDP Port 500, Protocol ID 50 and Protocol ID 51. ... Microsoft Certified Trainer ...
    (microsoft.public.windows.server.networking)
  • Re: VPN with ADSL
    ... This is not an UDP port 47 but an IP protocol 47. ... SOHO router might have the settings for IPSec pass-through and PPTP ...
    (microsoft.public.win2000.networking)
  • abort at the end of data transfer
    ... data chunk is i.e 6. ... int init_client(int port, char *ip) { ... Protocol Info ... Stream Control Transmission Protocol, Src Port: 1031, Dst Port: ...
    (comp.lang.c)