Hi All
I Found this while looking at the flow monitor.
Some UDP 5060 packets are reports as MagicJack.
See Pic.
Mark
tcpdump -s 0 -n -i any -w dumpfile.pcap udp and port 5060 or port 5070
I am sorry, but with the current information available I can't track down what's going wrong here. Can someone with a MagicJack device/account please provide me some packet dumps in a private message?
If it's getting false positives, then wouldn't you want the non MJ traffic that's triggering the MJ classification?