The Intranet Device Detects That The IAM Sent UDP Packets To The Intranet PC

|
  • 118
  • 6

Issue Description

The device is deployed in bypass mode. The intranet firewall detects that the IAM has sent UDP packets to different PCs on the intranet.

Handling Process

  • Capture data packets on the device interface. It is found that IAM actively sends data to different PCs on the intranet through UDP port 2330.
  • Check that IAM’s Audit Policy has checked “Access to unidentified applications (on which address and port. It incurs massive logs)“, and the device has checked “Report unidentified application” by default.



Root Cause

After selecting “Access to unidentified applications (on which address and port. It incurs massive logs)“, the device will audit the currently unrecognized data packet, record the address and port, and send a packet request to the PC through UDP port 2330. Application name, change mechanism helps IAM improve database.

Solution

  • The audit policy can be unchecked with the “Access to unidentified applications” option.
  • You can try to add this behavior to the trust list on the firewall, because the mechanism of IAM itself does not have a negative impact, just to improve the database.

Faisal Posted 17 Aug 2020 06:57
  
Thank you very much for the information ...
Faisal Posted 26 Oct 2020 08:41
  
Nice article ...
Faisal Posted 13 Dec 2020 13:01
  
Great info ...
Ellechar Lv4Posted 01 Feb 2021 16:24
  
Very nice infoooooooooooooooooooooooooooooo
Faisal Posted 16 Mar 2021 07:13
  
Very informative …
Faisal Posted 01 Jun 2021 12:26
  
Nice guidance ...

I want to write a case
Doc ID: 2402
Author: Newbie280530
Updated: 2019-12-23 15:19
Version: