Clicky

Greetings,

I have 2 windows xp (professional, sp3 all patched up, IE8 on a 2003 AD domain) that the firewall logs show a couple of attempts to connect on port 500 udp to every website the browser visits.  The only problem I see this causes is that it slows the initial loading of a page down.  If I stop IPSEC Services, the problem stops.  I have run several types of avscans and compared config to several machines that do not have the problem and I can find nothing unusual. These machines are always on the inside and there are no vpn's in use.

I know this must be obvious, but I sure can't see it.  Any help would be appreciated.

mike

asked 12/06/2011 03:56

drake100's gravatar image

drake100 ♦♦


3 Answers:
UDP Port 500 Uses

I would be concerned with this type of behaviour.  It is not the type of behaviour that would be expected from a browser.  The fact that it is going to port 500 on every website you visit seems to indicate that it is attempting to find a VPN connection to a compromised webserver.  

It would seem that you have a trojan despite your avscans.  Particularly if you have other identical configurations that do not show this behaviour.
link

answered

sweetfa2's gravatar image

sweetfa2

Found it.  Both computers had pelco dx8000 security camera software loaded on them at one time.  Although the software had been "uninstalled" there was still a widgy called "DX8000 IPSec Policy" that, when disabled, stops the port 500 traffic.  I knew it was right in front of me, good night's sleep and it jumped out at me!
I could have easily re-imaged these machines, but, it puts my mind at ease knowing the cause.  Sweetfa2-thank you for your comment and quick post.
link

answered 2011-12-06 at 13:50:34

drake100's gravatar image

drake100

self solved

link

answered 2011-12-07 at 04:31:41

drake100's gravatar image

drake100

Your answer
[hide preview]

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Tags:

×1

Asked: 12/06/2011 03:56

Seen: 234 times

Last updated: 12/12/2011 05:15