This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to Stop UDP 14675 waterfall

After months and months of teethgrinding and not finding a good solution, I now realy want to know what to do about a few problems I find in my UTM.

I have a NAS disk in my network configured with static IP / DNS / Gateway ip's . 
But something in this system is is continiously poking on the 255.255.255.255 broadcast adress. And this is driving me crazy.
 I would like to know what can be done about the constant flow of UDP pokes on port 14675 ??? There are pokes on the UDP 137 and 138 also. 

I tried firewall rules but this didn't help. 
I have NO WINS server installed (on windows2008) and the DHCP setting in my UTM (UTM is DHCP server) 
has wins on 0.0.0.0 and WINS Node type: B-Node (no WINS)

Here are the results of Network Protection on my UTM dashboard.
Source:
Total dropped packets: 28 226 
host: 192.x.x.x 
packets: 27130 
percentage: 96.12%

Destination:
Total dropped packets: 28 226 
dest1: udp/14675
destination: 255.255.255.255
packets: 25656
percentage: 90.89% 

dest2: udp/137
destination:  Internal (LAN) (Broadcast)
packets: 1080
percentage: 3.83 %
 
UTM Version: 9.105-9


This thread was automatically locked due to age.
Parents
  • The message spoofed packet seems to indicate that your nas either has an (extra) ip-address in a different subnet or maybe you have another host with the same mac and/or IP-address.
    Spoofing means that the host is trying to imitate being someone else.

    Managing several Sophos UTMs and Sophos XGs both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

    Sometimes I post some useful tips on my blog, see blog.pijnappels.eu/category/sophos/ for Sophos related posts.

Reply
  • The message spoofed packet seems to indicate that your nas either has an (extra) ip-address in a different subnet or maybe you have another host with the same mac and/or IP-address.
    Spoofing means that the host is trying to imitate being someone else.

    Managing several Sophos UTMs and Sophos XGs both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

    Sometimes I post some useful tips on my blog, see blog.pijnappels.eu/category/sophos/ for Sophos related posts.

Children
No Data