Windows firewall detected an application listening for incoming
Does the event provide additional details about what service is listening, it may be a domain related service, or something else valid. Use sysinternals process explorere it will give you mroe about what services are running under svchost etc It will show you what is using the resources of a specific generic process such as svchost. That or I am thinking of another product, but I am pretty sure it's processexplorer.
I believe LSASS is opening up a listener dynamically which explains the roaming, usually sequential-ish port numbers, but I'm not sure for what reason.
It could be related to user identification the User Service for Websense Web Security, but the logs are not giving me sufficient detail so far to determine that. To continue this discussion, please ask a new question. Get answers from your peers along with millions of IT pros who visit Spiceworks.
My question is is Event ID in the Security section a real problem? Friday, October 5, AM. Terms of Use. Privacy Statement. I enabled pfirewall. It did not create the log file! I put the netsh commands you suggested in a batch file and redirected the output to a file. Below is the output. Thanks, Paul. Instances of this are logged regularly every few minutes, sometimes in clusters at seemingly random intervals and for seemingly random ports.
All this when the machine is theoretically idle waiting for me to debug it : pfirewall. Today, for some reason, it is successfully launching the server process non-interactively on the server in question.
This is despite the firewall activity. Is there something sporadic going on here? Yet today, it is consistently working with the Windows Firewall service enabled. Sorry for the late response, I took sick leave at home yesterday.
I am not sure if I have understood you completely. Do you mean that the problem suddenly go away mystically? I get this question because I see you replied with "Yet today, it is consistently working with. Do you still need any help on this issue? If so, please feel free to tell me, I will collaborate with the Windows firewall team to resolve this problem. And, could this explain a failure to launch? I'd hate the resolution to be disabling the Windows Firewall service without even understanding what the problem is.
Up until now, I have been describing one server let's call it "server2". Note: Any data files that are infected may only be cleaned by deleting the file entirely, which means there is a potential for data loss. Was this reply helpful? Yes No. Sorry this didn't help. Thanks for your feedback. I am having a Failure Audit in Security, what can be done?
This thread is locked.