PDA

View Full Version : Lots of unknown UDP block


JaXXX
July 14th, 2009, 03:21 PM
Hi all.

When I go to the firewall log I see this:
14-7-2009 22:17:26 No usable rule found 192.168.0.198:60636 224.0.0.252:5355 UDP C:\Windows\System32\svchost.exe NT AUTHORITY\NETWORK SERVICE
14-7-2009 22:17:26 No usable rule found fe80::5030:660c:edba:cb0f.:58306 ff02::1:3.:5355 UDP C:\Windows\System32\svchost.exe NT AUTHORITY\NETWORK SERVICE
14-7-2009 22:17:26 No usable rule found 192.168.0.198:60636 224.0.0.252:5355 UDP C:\Windows\System32\svchost.exe NT AUTHORITY\NETWORK SERVICE
14-7-2009 22:17:26 No usable rule found fe80::5030:660c:edba:cb0f.:58306 ff02::1:3.:5355 UDP C:\Windows\System32\svchost.exe NT AUTHORITY\NETWORK SERVICE
14-7-2009 22:17:26 No usable rule found fe80::5030:660c:edba:cb0f.:49153 ff02::c.:3702 UDP C:\Windows\System32\svchost.exe NT AUTHORITY\LOCAL SERVICE
14-7-2009 22:17:26 No usable rule found 192.168.0.198:49152 239.255.255.250:3702 UDP C:\Windows\System32\svchost.exe NT AUTHORITY\LOCAL SERVICE
14-7-2009 22:17:26 No usable rule found fe80::5030:660c:edba:cb0f.:49153 ff02::c.:3702 UDP C:\Windows\System32\svchost.exe NT AUTHORITY\LOCAL SERVICE
14-7-2009 22:17:26 No usable rule found 192.168.0.198:49152 239.255.255.250:3702 UDP C:\Windows\System32\svchost.exe NT AUTHORITY\LOCAL SERVICE


It just keeps on refreshing and adding more of this. What is this? I think this is just for Firefox or some Windows networking service. I would like to disable the rule, but it doesn't say what it is.

Does anybody recognize this problem? I am running Eset Smart Security 4 with latest updates installed. (Edit: on Vista SP2)

Thanks in advance

JaXXX
July 14th, 2009, 03:28 PM
I found out happens when an other computer within the network refreshes the Network page and scans for other computers. Other computers will not see this computer on the list.
I have disabled:
block incoming netbios requests
block outgoing netbios requests
block netbios name service requests
block incoming ssdp (upnp) requests
block outgoing ssdp (upnp) requests
It didn't solve the problem :(

The problem is it doesn't say what rule blocks it.

Marcos
July 14th, 2009, 04:33 PM
Does switching to interactive mode help? The thing is unititiated incoming connections are blocked in automatic mode which results in the "No usable rule found" messages.

JaXXX
July 14th, 2009, 05:00 PM
Yes :) I got a few popups and told it to keep allowing it. Works great now, thanks!
Edit: I am getting this new one now...
14-7-2009 23:06:01 No usable rule found fe80::cad:f21d:132e:7b8c.:135 ff02::1:ff3b:85ef ICMPv6 System

silverfox55
July 16th, 2009, 03:31 PM
This problem has been going on for a long time. Another problem that ESET do not know how to fix. There have been various threads on this subject and ESET have not managed to offer any help or fix the problem.
ESET V3 on Vista. (V4 does not work properly yet )