Hi, the background for this topic can be found here but I wanted to ask another question about this:;msg483905#msg483905

This is really just for my own understanding. I set svchost.exe, system, explorer.exe to copy from outgoing only and removed the checkbox to “log as a firewall event if this rule is fired”.

I was just wondering what the methodology for setting it as outgoing only was? It is blocking quite a lot of traffic from the ip address of the router to my machine at the moment. The traffic seems to be on random port numbers like 60977, which I don’t use for anything that I know of.

Can you show a screenshot of the logs? That way we can see what the destination ports.

The Outgoing Only rule will protect these important Windows file from getting attacked.