Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Network Threat Protection traffic log shows Blocked Ethernet (type = 0x34) and (type = 0x5c)

Updated: 21 May 2010 | 13 comments
techcoor's picture
0 0 Votes
Login to vote

Network Threat Protection traffic log shows Blocked Ethernet (type = 0x34) and (type = 0x5c) from remote host 0.0.0.0.

What is this type of communication and what should I do about these types of communication?

Comments

Vikram Kumar-SAV to SEP's picture
12
Nov
2009
0 Votes 0
Login to vote

 Not sure what these Ethernet

 Not sure what these Ethernet Types are however does it show MAC addresses as well ?

techcoor's picture
13
Nov
2009
0 Votes 0
Login to vote

No MAC addresses

No MAC addresses (FF.FF.FF.FF.FF.FF)

shp's picture
12
Nov
2009
0 Votes 0
Login to vote

May be it is some type of

May be it is some type of broadcast...
Can you take a snap shot and upload here.... 

Regards,
Srinivas H.P.
HCL Infosystems Ltd

sandip_sali's picture
13
Nov
2009
0 Votes 0
Login to vote

Screenshot

Can you please post the screenshot which depicts the error message.

Thanks & Regards Sandip C Sali

techcoor's picture
13
Nov
2009
0 Votes 0
Login to vote

No, I have not figured how to

No, I have not figured how to get the BMP file uploaded. Can get the Insert image to work.

Jason1222's picture
13
Nov
2009
0 Votes 0
Login to vote

Ethernet (type = 0x34) and (type = 0x5c)

Is header information for the few few bits of data as defined in the IEEE 802.3 standard.
From hos 0.0.0.0 is likely to be multicast or broadcast information.

Have you modified the original Firewall Rules as set in the SEPM?

techcoor's picture
13
Nov
2009
0 Votes 0
Login to vote

No, I did not modified the

No, I did not modified the original Firewall Rules. The sample computer has version 11.0.5. I not sure what the M means after Symantec Endpoint Protection.

11/13/2009 15:26 Allowed 10 Incoming UDP 192.168.2.70 00-12-3F-8B-1F-CB 138 192.168.2.255 FF-FF-FF-FF-FF-FF 138 C:\WINDOWS\system32\ntoskrnl.exe User 27M1V71 Default 1 11/13/2009 15:26 11/13/2009 15:26 GUI%GUICONFIG#SRULE@NBENABLEYOU#ALLOW-UDP
11/13/2009 15:26 Allowed 10 Outgoing UDP 192.168.2.255 FF-FF-FF-FF-FF-FF 138 192.168.2.70 00-12-3F-8B-1F-CB 138 C:\WINDOWS\system32\ntoskrnl.exe User 27M1V71 Default 1 11/13/2009 15:26 11/13/2009 15:26 GUI%GUICONFIG#SRULE@NBENABLEYOU#ALLOW-UDP
11/13/2009 15:26 Blocked 10 Incoming ETHERNET [type=0x34] 0.0.0.0 00-0F-B5-88-D8-A9 0 0.0.0.0 FF-FF-FF-FF-FF-FF 0   User 27M1V71 Default 1 11/13/2009 15:26 11/13/2009 15:26 Block_all
11/13/2009 15:26 Blocked 10 Incoming ETHERNET [type=0x34] 0.0.0.0 00-0F-B5-88-D8-A9 0 0.0.0.0 FF-FF-FF-FF-FF-FF 0   User 27M1V71 Default 1 11/13/2009 15:25 11/13/2009 15:25 Block_all
11/13/2009 15:25 Blocked 10 Incoming ETHERNET [type=0x5C] 0.0.0.0 00-14-6C-E9-7C-45 0 0.0.0.0 FF-FF-FF-FF-FF-FF 0   User 27M1V71 Default 1 11/13/2009 15:24 11/13/2009 15:24 Block_all
11/13/2009 15:25 Blocked 10 Incoming ETHERNET [type=0x5C] 0.0.0.0 00-14-6C-E9-7C-45 0 0.0.0.0 FF-FF-FF-FF-FF-FF 0   User 27M1V71 Default 1 11/13/2009 15:24 11/13/2009 15:24 Block_all
11/13/2009 15:25 Blocked 10 Incoming ETHERNET [type=0x5C] 0.0.0.0 00-14-6C-E9-7C-45 0 0.0.0.0 FF-FF-FF-FF-FF-FF 0   User 27M1V71 Default 1 11/13/2009 15:24 11/13/2009 15:24 Block_all
11/13/2009 15:25 Allowed 10 Incoming UDP 192.168.2.61 00-14-6C-E9-7C-45 138 192.168.2.255 FF-FF-FF-FF-FF-FF 138 C:\WINDOWS\system32\ntoskrnl.exe User 27M1V71 Default 1 11/13/2009 15:24 11/13/2009 15:24 GUI%GUICONFIG#SRULE@NBENABLEYOU#ALLOW-UDP
shp's picture
13
Nov
2009
0 Votes 0
Login to vote

Go to command prompt and

Go to command prompt and trype arp -a
find out what is the ip related to "00-0F-B5-88-D8-A9", "00-14-6C-E9-7C-45"

then you can track the pc and check.
Make sure all windows patches are installed.
Also check AV Status.
 

Regards,
Srinivas H.P.
HCL Infosystems Ltd

techcoor's picture
17
Nov
2009
0 Votes 0
Login to vote

The command arp -a will not

The command arp -a will not help as the computer was turned off and the table is almost empty.

The associated IP can be found by looking at the router DHCP and matching the MAC address,

then computer name can be found from nbtstat -A <Ip address>

But what good does this do me? I only know which computers are involved but not the application that is being blocked. 

I was not able to upload an image.

sri2384's picture
18
Nov
2009
0 Votes 0
Login to vote

The MAC address specified in

The MAC address specified in the Traffic log (00-0F-B5-88-D8-A9 and 00-14-6C-E9-7C-45)belongs to Netgear . MAC addresses can be verified from the following link www.coffer.com/mac_find/

check if any Netgear hardware is installed ??

Also i think ethernet type 0x34 and 0x5C belong to IEEE as the Ethernet type range (0x0000 - 0x05DC IEEE 802.3 length). Check this link for all ethernet types. www.networkdictionary.com/networking/EtherType.php

Let me know if this actually hepled you

techcoor's picture
19
Nov
2009
0 Votes 0
Login to vote

Yes, these Macs are Netgear

Yes, these Macs are Netgear for WPM311 and WG111T respectively.

I not seeing anything I can used from the link.

 

sri2384's picture
18
Nov
2009
0 Votes 0
Login to vote

The entries in the log about

The entries in the log about ntoskrnl.exe are normal about any firewall.This log will be generated even if no rules are configured. Because the firewall is by default configured to check the UDP traffic. You will find this kind of ntoskrnl.exe (UDP) log even from Windows Firewall.

techcoor's picture
19
Nov
2009
0 Votes 0
Login to vote

The entry containing the

The entry containing the ntoskrnl.exe is not blocked. The blocked messages may or may not have a ntoskrnl.exe nearby from the same MAC.