cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
440
Views
0
Helpful
1
Replies

Strange UDP port...

wconnaughton
Level 1
Level 1

Hello,

Can anyone assit with this? Getting warning in syslog that UDP port 56616 is being blocked by ACL. I just tok a look and noticed that UDP port 56616 is reserved for private port. Anyone know what this could be as well as the source?

02-12-2007 00:10:30 Local4.Warning pix515.XXXXX.com %PIX-4-106023: Deny udp src outside:192.168.1.1 (XXX.XXXXX.com) /56616 dst inside:***DC2/514 by access-group "outside_access_in" [0x0, 0x0]

1 Reply 1

lgijssel
Level 9
Level 9

What matters here is the destination port.

This is port 514, used by syslog.

ftp://ftp.rfc-editor.org/in-notes/rfc1700.txt

It seems as if a device on the outside perimeter is trying to write to your syslog server.

Regards,

Leo