<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CSA UDP1900?? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/csa-udp1900/m-p/608034#M94865</link>
    <description>&lt;P&gt;Hello, I realise that this is generated by windows machines for SSDP/MSN.  How can I stop these machines from generating this / what is the easiest way to stop these events from coming accross -I seem to get +-100 / day for a 15 user network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;81 17/05/2006 11:35:43 TK01&lt;/P&gt;&lt;P&gt;&amp;lt;&lt;A class="jive-link-custom" href="https://192.168.50.16/csamc45/webadmin?page=host_view&amp;amp;id=119" target="_blank"&gt;https://192.168.50.16/csamc45/webadmin?page=host_view&amp;amp;id=119&lt;/A&gt;&amp;gt; Alert The process 'C:\WINDOWS\system32\svchost.exe' (as user NT AUTHORITY\LOCAL SERVICE) attempted to communicate with 192.168.50.14 &amp;lt;javascript:resolveIPAddress('192.168.50.14');&amp;gt; on UDP port 1900. The attempted access was to accept a connection as a server (operation = ACCEPT). The operation was denied. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;Shervan&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 10:01:15 GMT</pubDate>
    <dc:creator>Shervan Singh</dc:creator>
    <dc:date>2019-03-10T10:01:15Z</dc:date>
    <item>
      <title>CSA UDP1900??</title>
      <link>https://community.cisco.com/t5/network-security/csa-udp1900/m-p/608034#M94865</link>
      <description>&lt;P&gt;Hello, I realise that this is generated by windows machines for SSDP/MSN.  How can I stop these machines from generating this / what is the easiest way to stop these events from coming accross -I seem to get +-100 / day for a 15 user network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;81 17/05/2006 11:35:43 TK01&lt;/P&gt;&lt;P&gt;&amp;lt;&lt;A class="jive-link-custom" href="https://192.168.50.16/csamc45/webadmin?page=host_view&amp;amp;id=119" target="_blank"&gt;https://192.168.50.16/csamc45/webadmin?page=host_view&amp;amp;id=119&lt;/A&gt;&amp;gt; Alert The process 'C:\WINDOWS\system32\svchost.exe' (as user NT AUTHORITY\LOCAL SERVICE) attempted to communicate with 192.168.50.14 &amp;lt;javascript:resolveIPAddress('192.168.50.14');&amp;gt; on UDP port 1900. The attempted access was to accept a connection as a server (operation = ACCEPT). The operation was denied. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;Shervan&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:01:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-udp1900/m-p/608034#M94865</guid>
      <dc:creator>Shervan Singh</dc:creator>
      <dc:date>2019-03-10T10:01:15Z</dc:date>
    </item>
    <item>
      <title>Re: CSA UDP1900??</title>
      <link>https://community.cisco.com/t5/network-security/csa-udp1900/m-p/608035#M94866</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;UDP 1900 is used by the Windows, e.g Windows XP, for SSDP Discovery Service. This is to enable discovery of UPnP devices in the network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can stop a machine from activating/running this service from the Control Panel - Administrative Tools - Services. Look for "SSDP Discovery Service". Double-clik and set the 'Startup type' either as manual or disabled. BY default, SSDP is enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Before you stop this service, check the service status from MSDOS prompt using 'netstat -a' command. If this service is running, you should see something like "UDP &lt;HOSTNAME&gt;:1900 *:*".&lt;/HOSTNAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stop the service, and run the netstat command again to verify whether the 1900 service is still running or disabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 May 2006 02:53:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-udp1900/m-p/608035#M94866</guid>
      <dc:creator>a.kiprawih</dc:creator>
      <dc:date>2006-05-18T02:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: CSA UDP1900??</title>
      <link>https://community.cisco.com/t5/network-security/csa-udp1900/m-p/608036#M94867</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you don't want to turn the service off, you can create another rule that is set to deny (not high priority deny) svchost.exe accepting connections on UDP 1900, set to not log and set to take precedence over other deny rules. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only time this will log is when machines are in test mode and then the only place you see messages is on the MC. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom S&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 May 2006 04:14:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-udp1900/m-p/608036#M94867</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2006-05-18T04:14:18Z</dc:date>
    </item>
  </channel>
</rss>

