... Expand / Collapse
Author
Message
Posted 6/22/2015 3:06:49 AM
Forum Newbie

Forum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum Newbie

Group: Forum Members
Last Login: 6/22/2015 4:56:18 AM
Posts: 1, Visits: 3
Hi Team,

Receiving huge no.of logs on a windows server, Request your help to validate and  Any clue on this pattern and how this getting initiated.

"The Windows Filtering Platform blocked a packet.  Application Information:  Process ID:  0   Application Name: -   Network Information:  Direction:  Inbound   Source Address:  127.0.0.1   Source Port:  54902   Destination Address: 127.0.0.1   Destination Port:  600   Protocol:  17   Filter Information:  Filter Run-Time ID: 65884   Layer Name:  Transport   Layer Run-Time ID: 13"

Regards,

Ravi

Post #3269
Posted 7/26/2015 8:57:10 PM
Supreme Being

Supreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme Being

Group: Moderators
Last Login: 11/14/2013 3:17:47 PM
Posts: 237, Visits: 0
This is a Windows Firewall log, if you are not interested in this data then disable auditing of this sub category. https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5152 shows you the category and subcategory to disable.
Post #4625
« Prev Topic | Next Topic »


Permissions Expand / Collapse

All times are GMT -5:00, Time now is 3:01am