UDP traffic is getting past external firewall

abujanan

Junior Member
May 2, 2006
3
0
0
I have two XP/pro systems running ZoneAlarm Pro (Windows firewall turned-off) connected to a Hawking PN9239 4-port dsl/cable firewall router which is in turn connected to a Motorola Surfboard cable modem.

I've set ZoneAlarm to log all blocked events and have found UDP traffic is consistently being logged (ie. getting past the PN9239).

I've installed the latest firmware and re-set/reconfigured the PN9239 several times without resolution. It is DHCP enabled and dynamically assigning ip. My cable isp also assigns dynamically.

I've used "netstat -a 1" and ZA pop-up alerts to see if the UDP traffic is replies to call-outs from my computer but this is not the case.

Besides, say my computer is making call outs, if ZA is configured tight enough to catch the incoming UDP traffic (by default), shouldn't my PN9239 do as much?

I hope someone here can help me get this firewall to do it's job properly.
 

blemoine

Senior member
Jul 20, 2005
312
0
0
ZA is configured tight enough to catch the incoming UDP traffic (by default), shouldn't my PN9239 do as much?

Who knows?
Who Cares?

If your worried about security. get a hardware firewall or build one that uses IP Tables for filtering & Snort for intrusion detection. that should be more than enough to secure you past anything you will ever need. dump the zone alarm. you will be happier.



 

JackMDS

Elite Member
Super Moderator
Oct 25, 1999
29,554
430
126
Originally posted by: abujananIf ZA is configured tight enough to catch the incoming UDP traffic (by default), shouldn't my PN9239 do as much?
Welcome To AT Network Forum.

NAT Firewall (deals only with Internet traffic) it blocks every thing by default, and lets every think in if it comes from an Internet Site that you log to. ( http://www.ezlan.net/firewall.html ).

If you did not open any port (and UnPnP is off), nothing comes through the Router, unless it is send by a site that you logged to on your own volition.

Software Firewall examines the traffic that comes in and out a specific computer, and thus can filter, block, allow, etc., any thing that its configuration to, from and to, the Internet and the LAN.

:sun:
 

abujanan

Junior Member
May 2, 2006
3
0
0
to nweaver - i don't block the lan traffic. googling the ips indicate a majority originate from china sites.

to blemoine - i'll look into your advice.

to JackMDS - thanks for a refreshing 101... plain and simply explained.

anyway, i've been advised to compare logs from netstat, za, and the pn9239 to verify whether i'm calling-out or not.
 

abujanan

Junior Member
May 2, 2006
3
0
0
It turned out to be calls from svchost (running the network apps), my anti-malware and firefox.