Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 22, 2013, 06:58:41 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
663622
Posts
70564
Topics
145224
Members
Latest Member:
zukutome
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Internet Security - CIS
Help - CIS
Firewall Help - CIS
system is trying to receive a connection from the internet upnp/ssdp(2869)?
« previous
next »
Pages:
[
1
]
Author
Topic: system is trying to receive a connection from the internet upnp/ssdp(2869)? (Read 4357 times)
stuartf1
Newbie
Offline
Posts: 9
system is trying to receive a connection from the internet upnp/ssdp(2869)?
«
on:
February 23, 2012, 07:22:46 PM »
I got a pop up on this a few times now. Not sure what to do . Earlier today I read through some posts here and one said system should only have outgoing set, so I went ahead and set system and svchost in Comodo Firewall for outgoing only.
Could this possibly be something suspicious?
TIA
Stuart
Logged
Radaghast
Star Group
Comodo's Hero
Offline
Posts: 4036
Re: system is trying to receive a connection from the internet upnp/ssdp(2869)?
«
Reply #1 on:
February 23, 2012, 07:30:09 PM »
Quote from: stuartf1 on February 23, 2012, 07:22:46 PM
I got a pop up on this a few times now. Not sure what to do . Earlier today I read through some posts here and one said system should only have outgoing set, so I went ahead and set system and svchost in Comodo Firewall for outgoing only.
Could this possibly be something suspicious?
TIA
Stuart
Receiving connections from other plug and play devices on the LAN, over TCP 2869, is quite normal. Two questions:
1. Do you have a router?
2. Do you use UPnP?
Logged
“Don’t worry if it doesn’t work right. If everything did, you’d be out of a job.”
stuartf1
Newbie
Offline
Posts: 9
Re: system is trying to receive a connection from the internet upnp/ssdp(2869)?
«
Reply #2 on:
February 23, 2012, 07:37:31 PM »
Quote from: Radaghast on February 23, 2012, 07:30:09 PM
Receiving connections from other plug and play devices on the LAN, over TCP 2869, is quite normal. Two questions:
1. Do you have a router?
2. Do you use UPnP?
Yes I have a router.
Yes I use UPnP.
Stuart
Logged
Radaghast
Star Group
Comodo's Hero
Offline
Posts: 4036
Re: system is trying to receive a connection from the internet upnp/ssdp(2869)?
«
Reply #3 on:
February 23, 2012, 10:43:24 PM »
Quote from: stuartf1 on February 23, 2012, 07:37:31 PM
Yes I have a router.
Yes I use UPnP.
Stuart
These are probably SSDP event notifications from your router. For UPnP/SSDP to work correctly, you should allow these, but it probably won't cause any considerable problems if you continue to block the requests. Your choice.
Logged
“Don’t worry if it doesn’t work right. If everything did, you’d be out of a job.”
stuartf1
Newbie
Offline
Posts: 9
Re: system is trying to receive a connection from the internet upnp/ssdp(2869)?
«
Reply #4 on:
February 26, 2012, 06:47:14 PM »
Quote from: Radaghast on February 23, 2012, 10:43:24 PM
These are probably SSDP event notifications from your router. For UPnP/SSDP to work correctly, you should allow these, but it probably won't cause any considerable problems if you continue to block the requests. Your choice.
Thank you. I went ahead and accepted.
Stuart
Logged
aguyonapc
Newbie
Offline
Posts: 13
Re: system is trying to receive a connection from the internet upnp/ssdp(2869)?
«
Reply #5 on:
February 26, 2012, 08:38:33 PM »
I'm dealing with the same thing here (I think) but I'm not sure why it's happening as it's pretty recent.
I do have UPnP enabled, and my modem is a Cisco DPC3825 Gateway.
I switched to ComodoDNS and am wondering if it's got something to do with that.
My first alert was svchost.exe trying to connect to 57058. I blocked that for a while, but did end up allowing it once. After that I started seeing system trying to connect to 2869. I've been blocking it as I'm not sure exactly what it is. Should it be ok to allow?
«
Last Edit: February 26, 2012, 08:41:33 PM by aguyonapc
»
Logged
Radaghast
Star Group
Comodo's Hero
Offline
Posts: 4036
Re: system is trying to receive a connection from the internet upnp/ssdp(2869)?
«
Reply #6 on:
February 26, 2012, 09:03:43 PM »
Quote from: aguyonapc on February 26, 2012, 08:38:33 PM
I'm dealing with the same thing here (I think) but I'm not sure why it's happening as it's pretty recent.
I do have UPnP enabled, and my modem is a Cisco DPC3825 Gateway.
I switched to ComodoDNS and am wondering if it's got something to do with that.
My first alert was svchost.exe trying to connect to 57058. I blocked that for a while, but did end up allowing it once. After that I started seeing system trying to connect to 2869. I've been blocking it as I'm not sure exactly what it is. Should it be ok to allow?
The DNS service will connect outbound via UDP to port 53 and the addresses used, last time I looked, were:
8.26.56.26
156.154.70.22
Other than that, svchost, along with other system services, use ports from the dynamic range (49152-65535) for a variety of things, so we'd need more information to determine the precise nature of the connection.
With regard to the SSDP/UPnP connection, these are typically event notifications, basically, just a UPnP enabled device, letting other similar devices, know it's alive. If you're using UPnP you should probably allow the connections, but it's worth making sure you know where the connections are coming from.
Logged
“Don’t worry if it doesn’t work right. If everything did, you’d be out of a job.”
aguyonapc
Newbie
Offline
Posts: 13
Re: system is trying to receive a connection from the internet upnp/ssdp(2869)?
«
Reply #7 on:
February 27, 2012, 06:50:44 PM »
I just logged into windows and got over 60 (so far) events logged.
Windows Operating System
Action - Blocked
Protocol - TCP
Source IP - 192.168.0.1
Source Port - 1099, 1100, 1101, 1102, 1103
Destination IP - 192.168.0.10
Destination Port - 2869
How do I get this to stop exactly.
I blocked it sometime yesterday and obviously need to unblock it (if it's safe to do so).
I did delete some rules that showed up (started another thread on that issue).
https://forums.comodo.com/firewall-help-cis/where-did-these-rules-come-from-t82344.0.html
Perhaps that may have something do do with this?
«
Last Edit: February 27, 2012, 06:53:31 PM by aguyonapc
»
Logged
Radaghast
Star Group
Comodo's Hero
Offline
Posts: 4036
Re: system is trying to receive a connection from the internet upnp/ssdp(2869)?
«
Reply #8 on:
February 27, 2012, 07:26:40 PM »
Quote from: aguyonapc on February 27, 2012, 06:50:44 PM
I just logged into windows and got over 60 (so far) events logged.
Windows Operating System
Action - Blocked
Protocol - TCP
Source IP - 192.168.0.1
Source Port - 1099, 1100, 1101, 1102, 1103
Destination IP - 192.168.0.10
Destination Port - 2869
How do I get this to stop exactly.
I blocked it sometime yesterday and obviously need to unblock it (if it's safe to do so).
I did delete some rules that showed up (started another thread on that issue).
https://forums.comodo.com/firewall-help-cis/where-did-these-rules-come-from-t82344.0.html
Perhaps that may have something do do with this?
I'm guessing 192.168.0.1 is your router, if so, you need to check the documentation, for the device, to find out how to enable/disable/control UPnP.
Logged
“Don’t worry if it doesn’t work right. If everything did, you’d be out of a job.”
aguyonapc
Newbie
Offline
Posts: 13
Re: system is trying to receive a connection from the internet upnp/ssdp(2869)?
«
Reply #9 on:
February 27, 2012, 07:29:39 PM »
Ok I will do that.
Any idea why that would just start happening?
It finally stopped after 214 log entries.
All I did was remake the rules I had deleted (from other thread).
Not really sure if that's what fixed it though.
Source Port kept changing... went from 1099 up to 1129.
All other info stayed the same.
View Active Connections showed a connection to 188.121.36.239:80 (after the alerts stopped... may or may not be related).
«
Last Edit: February 27, 2012, 07:31:11 PM by aguyonapc
»
Logged
Radaghast
Star Group
Comodo's Hero
Offline
Posts: 4036
Re: system is trying to receive a connection from the internet upnp/ssdp(2869)?
«
Reply #10 on:
February 27, 2012, 09:06:05 PM »
Quote from: aguyonapc on February 27, 2012, 07:29:39 PM
Ok I will do that.
Any idea why that would just start happening?
It finally stopped after 214 log entries.
All I did was remake the rules I had deleted (from other thread).
Not really sure if that's what fixed it though.
Source Port kept changing... went from 1099 up to 1129.
All other info stayed the same.
As I mentioned earlier, these log entries just show SSDP event notifications. Generally, these are in response to a query, sent out by some other UPnP enabled device on your network. On a PC, svchost usually takes responsibility for UPnP/SSDP related connections. If you're using default firewall rules, svchost is allowed to make outbound connections, so seeing your inbound connections as a response, is not really surprising.
If you're not using UPnP, in addition to disabling the option in your router, you can open services.msc from Start/Run and disable the UPnP and SSDP services.
Quote
View Active Connections showed a connection to 188.121.36.239:80 (after the alerts stopped... may or may not be related).
Unlikely, the address belongs to GoDaddy, so this is probably a certificate check. Just another normal part of the OS connectivity.
Logged
“Don’t worry if it doesn’t work right. If everything did, you’d be out of a job.”
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 2.766 seconds with 23 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com