Security Audit Event 5152.  Is this a concern?

J.R. Sitman
J.R. Sitman used Ask the Experts™
on
I'm getting the attached event.  Do I need to be concerned?
audit.jpg
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
systechSenior Technical Lead

Commented:
Hi,

This looks like the windows firewall hasn't set correctly for the inbound traffic. Also, it could be edge traversal settings. Have a look at this MS article and try to set edge traversal and see it stops the event.
 http://technet.microsoft.com/en-us/library/ee649264(v=ws.10).aspx
J.R. SitmanIT Director

Author

Commented:
The Windows firewall on that server is off.  If it's not a concern, then I can just ignore it, correct?
Senior Technical Lead
Commented:
Hi,

Thanks for your reply. Bur unfortunately this event required attention as it's indicates that there is a inbound packet blocked by windows filtering. It could be a attempt of hacking.

Also, the windows firewall service in question should be on in windows 2008 environment. You can also refer this tech article and install the required hotfix (the error events are same)
http://support.microsoft.com/kb/2654852

Hope this helps
Acronis in Gartner 2019 MQ for datacenter backup

It is an honor to be featured in Gartner 2019 Magic Quadrant for Datacenter Backup and Recovery Solutions. Gartner’s MQ sets a high standard and earning a place on their grid is a great affirmation that Acronis is delivering on our mission to protect all data, apps, and systems.

Top Expert 2012
Commented:
I tried to get WHOIS listing of 239.255.255.250 but could not find any details and the port 138 is used by NetBIOS  protocol used for File and Print Sharing under all current versions of Windows.

As this public IP is not from valid source it may be attempt of attack so would recommend you to check impact by blocking this IP on your external firewall and run full AV scan in safe mode
J.R. SitmanIT Director

Author

Commented:
I applied the patch.  I'll monitor it and post later.

Thanks
J.R. SitmanIT Director

Author

Commented:
Thanks.  I applied the patch and blocked the ip address.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial