Since i updated the Symantec Endpoint I've been getting network traffic block from svchost.exe UDP incoming 192.100.103.91 on port 1900 from all my clients. When i run backtrace it doesn't tell me who ip it is and its. Also now i get a block from NTOSKRNL.EXE. I wanted to know why is this happening with the new update because i never had a problem before the update.
This is the UPnP protocol. The default is to block it non-private IP ranges as it is vulnerable.
http://en.wikipedia.org/wiki/Universal_Plug_and_Play