unusual port 500 IPSEC traffic

Greetings,

I have 2 windows xp (professional, sp3 all patched up, IE8 on a 2003 AD domain) that the firewall logs show a couple of attempts to connect on port 500 udp to every website the browser visits.  The only problem I see this causes is that it slows the initial loading of a page down.  If I stop IPSEC Services, the problem stops.  I have run several types of avscans and compared config to several machines that do not have the problem and I can find nothing unusual. These machines are always on the inside and there are no vpn's in use.

I know this must be obvious, but I sure can't see it.  Any help would be appreciated.

mike
drake100Asked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

sweetfa2Commented:
UDP Port 500 Uses

I would be concerned with this type of behaviour.  It is not the type of behaviour that would be expected from a browser.  The fact that it is going to port 500 on every website you visit seems to indicate that it is attempting to find a VPN connection to a compromised webserver.  

It would seem that you have a trojan despite your avscans.  Particularly if you have other identical configurations that do not show this behaviour.
drake100Author Commented:
Found it.  Both computers had pelco dx8000 security camera software loaded on them at one time.  Although the software had been "uninstalled" there was still a widgy called "DX8000 IPSec Policy" that, when disabled, stops the port 500 traffic.  I knew it was right in front of me, good night's sleep and it jumped out at me!
I could have easily re-imaged these machines, but, it puts my mind at ease knowing the cause.  Sweetfa2-thank you for your comment and quick post.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
drake100Author Commented:
self solved
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Internet Protocol Security

From novice to tech pro — start learning today.