Morning,
I'm currently looking at Sophos Client Firewall for our laptop users, but my question is more related to networking in general I think. I'm running it in default mode for now to analyse the type of traffic coming in/out of the client. Our LAN is on 192.168.0.x, 255.255.255.0.
The following entries have been blocked, I'm ideally looking for a brief explanation of what they might be and whether I should be allowing them; the time period (9.03 to 9.10am) included powering on, logging on, and loading up Outlook. I've got VMWare installed on the laptop, but no VMs running at powerup.
09:09:57 netbios IN REFUSED UDP 172.50.10.1 NETBIOS_DGM Block NetBIOS Traffic
09:09:57 netbios IN REFUSED UDP 172.50.10.3 NETBIOS_DGM Block NetBIOS Traffic
09:09:57 netbios IN REFUSED UDP 172.50.10.5 NETBIOS_DGM Block NetBIOS Traffic
09:09:57 netbios IN REFUSED UDP 172.50.10.4 NETBIOS_DGM Block NetBIOS Traffic
09:09:57 netbios IN REFUSED UDP 172.50.10.2 NETBIOS_DGM Block NetBIOS Traffic
09:08:40 svchost.exe IN REFUSED UDP 192.168.1.254 1900 Block All Activity
09:07:23 system IN REFUSED UDP localhost(any) BOOTPC Block All Activity
09:06:54 netbios IN REFUSED UDP 172.50.10.4 NETBIOS_DGM Block NetBIOS Traffic
09:05:42 system IN REFUSED UDP localhost(any) BOOTPC Block All Activity
09:04:32 netbios OUT REFUSED UDP 192.168.234.255 NETBIOS_NS Block NetBIOS Traffic
09:04:29 netbios OUT REFUSED UDP 192.168.198.255 NETBIOS_NS Block NetBIOS Traffic
09:04:27 system IN REFUSED UDP 192.168.198.1 1119 Block All Activity
09:04:27 system IN REFUSED UDP 192.168.234.1 1120 Block All Activity
09:04:18 svchost.exe IN REFUSED UDP 192.168.198.1 1119 Block All Activity
09:04:18 system IN REFUSED UDP localhost 1122 Block Transit Packets
09:04:18 svchost.exe IN REFUSED UDP 192.168.234.1 1120 Block All Activity
09:04:09 system IN REFUSED UDP localhost 1099 Block Transit Packets
09:04:08 system OUT REFUSED IGMP 224.0.0.22 0 Learning Mode
09:04:08 system OUT REFUSED IGMP 224.0.0.22 0 Learning Mode
09:04:08 system OUT REFUSED IGMP 224.0.0.22 0 Learning Mode
09:03:44 netbios OUT REFUSED UDP 192.168.198.1 NETBIOS_NS Block NetBIOS Traffic
09:03:44 netbios OUT REFUSED UDP 192.168.198.1 NETBIOS_NS Block NetBIOS Traffic
09:03:44 netbios OUT REFUSED UDP 192.168.198.1 NETBIOS_NS Block NetBIOS Traffic
09:03:39 netbios OUT REFUSED UDP 192.168.234.1 NETBIOS_NS Block NetBIOS Traffic
09:03:39 netbios OUT REFUSED UDP 192.168.234.1 NETBIOS_NS Block NetBIOS Traffic
09:03:39 netbios OUT REFUSED UDP 192.168.234.1 NETBIOS_NS Block NetBIOS Traffic
09:03:33 netbios OUT REFUSED UDP 192.168.234.255 NETBIOS_DGM Block NetBIOS Traffic
09:03:33 netbios OUT REFUSED UDP 192.168.198.255 NETBIOS_DGM Block NetBIOS Traffic
09:03:09 netbios OUT REFUSED UDP 192.168.234.255 NETBIOS_NS Block NetBIOS Traffic
09:03:06 netbios OUT REFUSED UDP 192.168.198.255 NETBIOS_NS Block NetBIOS Traffic
Regards,
Chris.
Start Free Trial