?
Solved

Windows 7 Port 1900UDP Linksys RV042 Synflood Alerts?

Posted on 2010-08-16
5
Medium Priority
?
1,748 Views
Last Modified: 2012-05-10
Hello Experts,

I'm getting from my RV042 router alerts about synflooding that's occuring on the network... here's a sample of the log:

Sun Aug 15 22:04:35 2010
RGFW-IN: BLOCK-RULES (UDP 192.168.1.25:1900->239.255.255.250:1900 on ixp1) [20,1]
Sun Aug 15 22:04:35 2010
RGFW-RATELIMIT: 2 messages of type BLOCK-SYNFLOOD reported 2 second(s) ago
Sun Aug 15 22:04:33 2010
RGFW-IN: BLOCK-RULES (UDP 192.168.1.25:1900->239.255.255.250:1900 on ixp1) [20,1]
Sun Aug 15 22:04:33 2010
RGFW-RATELIMIT: 1 messages of type BLOCK-SYNFLOOD reported 1 second(s) ago
Sun Aug 15 22:04:32 2010
RGFW-IN: BLOCK-RULES (UDP 192.168.1.25:1900->239.255.255.250:1900 on ixp1) [20,1]
Sun Aug 15 22:04:32 2010
RGFW-RATELIMIT: 5 messages of type BLOCK-SYNFLOOD reported 29 second(s) ago
Sun Aug 15 22:04:03 2010
RGFW-IN: BLOCK-RULES (UDP 192.168.1.30:1900->239.255.255.250:1900 on ixp1) [20,1]
Sun Aug 15 22:04:03 2010
RGFW-RATELIMIT: 5 messages of type BLOCK-SYNFLOOD reported 3 second(s) ago
Sun Aug 15 22:04:00 2010
RGFW-IN: BLOCK-RULES (UDP 192.168.1.30:1900->239.255.255.250:1900 on ixp1) [20,1]
Sun Aug 15 22:04:00 2010
RGFW-RATELIMIT: 5 messages of type BLOCK-SYNFLOOD reported 3 second(s) ago
Sun Aug 15 22:03:57 2010
RGFW-IN: BLOCK-RULES (UDP 192.168.1.30:1900->239.255.255.250:1900 on ixp1) [20,1]
Sun Aug 15 22:03:57 2010
RGFW-RATELIMIT: 5 messages of type BLOCK-SYNFLOOD reported 85 second(s) ago
Sun Aug 15 22:02:31 2010
RGFW-IN: BLOCK-RULES (UDP 192.168.1.24:1900->239.255.255.250:1900 on ixp1) [20,1]
Sun Aug 15 22:02:31 2010
RGFW-RATELIMIT: 5 messages of type BLOCK-SYNFLOOD reported 3 second(s) ago
Sun Aug 15 22:02:29 2010
RGFW-IN: BLOCK-RULES (UDP 192.168.1.24:1900->239.255.255.250:1900 on ixp1) [20,1]
Sun Aug 15 22:02:29 2010
RGFW-RATELIMIT: 5 messages of type BLOCK-SYNFLOOD reported 3 second(s) ago
Sun Aug 15 22:02:26 2010
RGFW-IN: BLOCK-RULES (UDP 192.168.1.24:1900->239.255.255.250:1900 on ixp1) [20,1]
Sun Aug 15 21:57:19 2010
RGFW-IN: BLOCK-RULES (UDP 192.168.1.25:1900->239.255.255.250:1900 on ixp1) [20,1]
Sun Aug 15 21:57:18 2010
RGFW-IN: BLOCK-RULES (UDP 192.168.1.25:1900->239.255.255.250:1900 on ixp1) [20,1]
Sun Aug 15 21:57:18 2010
RGFW-RATELIMIT: 2 messages of type BLOCK-SYNFLOOD reported 1 second(s) ago
Sun Aug 15 21:57:17 2010
RGFW-IN: BLOCK-RULES (UDP 192.168.1.25:1900->239.255.255.250:1900 on ixp1) [20,1]
Sun Aug 15 21:57:17 2010
RGFW-RATELIMIT: 1 messages of type BLOCK-SYNFLOOD reported 1 second(s) ago
Sun Aug 15 21:57:16 2010
RGFW-IN: BLOCK-RULES (UDP 192.168.1.25:1900->239.255.255.250:1900 on ixp1) [20,1]
Sun Aug 15 21:57:15 2010
RGFW-IN: BLOCK-RULES (UDP 192.168.1.25:1900->239.255.255.250:1900 on ixp1) [20,1]
Sun Aug 15 21:57:15 2010
RGFW-RATELIMIT: 2 messages of type BLOCK-SYNFLOOD reported 1 second(s) ago
Sun Aug 15 21:57:14 2010

Note that 192.168.1.24, .25 and .30 are 3 windows 7 machines that were recently added to the network.  

I did a bit of googling and it looks like the machines might be generating UPnP traffic?  Can someone confirm this, and how would I go about stopping them from broadcasting this, so that my firewall log doesn't send me these what appear to be false positive alerts...

Thanks!
0
Comment
Question by:taki1gostek
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 5

Expert Comment

by:TechnicallyMaybe
ID: 33445757
You are correct about UPnP and SSDP using udp 1900.
If you don't want Windows 7 to discover network devices, disable SSDP Discovery service.
To disable UPnP, stop the UPnP Device Host service.
Set both service startup to disabled to prevent them from starting on next reboot.

Even with both services disabled, you still may see the broadcasts, if so, make the following reg change:
Hive: HKEY_LOCAL_MACHINE
Key: Software\Microsoft\DirectPlayNATHelp\DPNHUPnP
Name: UPnPMode
Type: REG_DWORD
Value: 2 disabled
With UPnPMode=2, Universal Plug and Play Network Address Translation (NAT) traversal discovery does not occur.
0
 
LVL 2

Author Comment

by:taki1gostek
ID: 33445976
thanks for the tip -- any chance I could make this happen using GP?
0
 
LVL 5

Expert Comment

by:TechnicallyMaybe
ID: 33447476
See the image for the location in GP to control services.

For the reg change.  You can create a .reg file and execute it through the logon script.
0
 
LVL 5

Accepted Solution

by:
TechnicallyMaybe earned 1000 total points
ID: 33447483
Sorry - here is the image I was referring to.
image15.png
0
 
LVL 2

Author Closing Comment

by:taki1gostek
ID: 33454210
Thanks, technically, maybe :)
0

Featured Post

Optimize your web performance

What's in the eBook?
- Full list of reasons for poor performance
- Ultimate measures to speed things up
- Primary web monitoring types
- KPIs you should be monitoring in order to increase your ROI

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
This program is used to assist in finding and resolving common problems with wireless connections.
In this brief tutorial Pawel from AdRem Software explains how you can quickly find out which services are running on your network, or what are the IP addresses of servers responsible for each service. Software used is freeware NetCrunch Tools (https…
If you’ve ever visited a web page and noticed a cool font that you really liked the look of, but couldn’t figure out which font it was so that you could use it for your own work, then this video is for you! In this Micro Tutorial, you'll learn yo…
Suggested Courses
Course of the Month15 days, 15 hours left to enroll

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question