Jump to content

Recommended Posts

Posted

Hello All,

 

I've got 2x Win 2008 R2 servers on our school network, during the working day, both servers get flooded with at least 20 thousand Event ID 5152s each in a single hour!

 

The IP address: 10.3.126.114 belongs to a staff laptop running Win7 Pro 64bit, and its last McAfee VirusScan 8.8 Patch 2 has come up negative for anything untoward.

 

I've Googled around the following;

Getting alot of Event ID 5152

Security Event ID 5152 by the thousands - Microsoft Community

Stuff I figured out.: Windows Auditing can be annoying. (Shut up already)

Notes on MS Integration, Administration, and Management: Resolve issue with multiple Event ID 5152 and 5157 appearing in the security event log

 

and some forums say its a MS server 2008 bug that requires a hotfix,

 

some say it's packets coming from Dropbox or Bonjour of the origin computer.

 

The port numbers don't clearly point to any specific program.

 

Lots of forums say, its harmless, and instruct to mute and ignore them.

I'd rather not mute them as it would mask any other problems.

 

None of these sites are giving a solid solution to the problem.

Anyone else come across this and wish to share their wisdom?

 

Am I making a mountain out of a mole hill? or is this something which can (or can't) be fixed?

 

-----I've copied and pasted one of the events for you to look at------

 

The Windows Filtering Platform has blocked a packet.

 

Application Information:

Process ID: 0

Application Name: -

 

Network Information:

Direction: Inbound

Source Address: 10.3.126.114

Source Port: 54799

Destination Address: 255.255.255.255

Destination Port: 2008

Protocol: 17

 

Filter Information:

Filter Run-Time ID: 4267779

Layer Name: Transport

Layer Run-Time ID: 13

---------------------------------------------------------------------

 

Any questions?

Posted
Why does a staff laptop have apple stuff and itunes anyhow?

 

Stay on topic please,

 

Staff take their laptops home, and some of them happen to use Apple products for teaching.

Posted (edited)

I had this from a similar - primary school staff laptop, iTunes installed. Disabling bonjour resolved it but to be honest I did little after that to investigate why. As bad as iAnything is when installed on a PC it can't be inherent to bonjour alone, I've installed it standalone on a couple of machines for them be used by iPads for Reflector (apple TV type software).

 

 

** edit - actually, this is a random thought but there's a distinct possibility said laptop was running McAfee. The desktops I installed bonjour on without issue were all System Center EP. It may help narrow down a search looking up bonjour + mcafee to see if there's any known issues there. Maybe coincidental but could be worth a look.

Edited by synaesthesia
Posted
Have you tried doing the process in the blogspot article? Ie. disable that type of firewall auditing? You don't say if you tried it or not.

I've tried, but decided to re-enable, as this doesn't fix the problem, only hides/masks it along with any other issue.

 

I had this from a similar - primary school staff laptop, iTunes installed. Disabling bonjour resolved it but to be honest I did little after that to investigate why. As bad as iAnything is when installed on a PC it can't be inherent to bonjour alone, I've installed it standalone on a couple of machines for them be used by iPads for Reflector (apple TV type software).

** edit - actually, this is a random thought but there's a distinct possibility said laptop was running McAfee. The desktops I installed bonjour on without issue were all System Center EP. It may help narrow down a search looking up bonjour + mcafee to see if there's any known issues there. Maybe coincidental but could be worth a look.

 

I'll have another look. afaik, I have removed all traces of Apple iTunes and bonjour from the laptop. Didn't think the McAfee VirusScan would have an affect as all the workstations on our domain are running it... nonetheless, stranger things have happened.

Posted

I've never come across this before, but this will give you a list of all ongoing connections on a machine (both outgoing and listening) and the process that created it:

 

netstat -b

 

At least you'll be able to narrow it down to process.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...