cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
greatscott
Level 12
Report Inappropriate Content
Message 1 of 3

Link Local Multicast Name Resolution v. HIPS Firewall et al

Anyone seen an issue with the HIPS Firewall, and processing of LLMNR traffic?  The traffic is tripping over our CAG, which has IP based criteria. A system hits the LLMNR and for some reason starts using a 224.x.x.x local address, which is not defined in our CAG. The top bit of traffic is a block shown when the traffic hits our top CAG, where connection isolation is checked. The second piece of traffic below is an allow, when we uncheck connection isolation in our top CAG. The traffic is processed by our lower CAG, which has DNS based criteria:

    Mode = traffic

    Process id = 1632

    Event type = FW_LOG_EVENT_TYPE_TRAFFIC

    Direction = FW_DIRECTION_INBOUND

    Action = FW_ACTION_BLOCK_PACKET

    Source port = 53865

    Dest port = 5355

    Ip protocol = 17

    Ethernet type = 0x800

    Process path = C:\WINDOWS\SYSTEM32\SVCHOST.EXE

    Local ip addr = 224.0.0.252

    Remote ip addr = XXX.XXX.240.166

    Source MAC = 00-00-00-00-00-00-00-00

    Dest MAC = 00-XX-e8-XX-36-XX-00-XX

    Mode = traffic
    Process id = 1632
    Event type = FW_LOG_EVENT_TYPE_TRAFFIC
    Direction = FW_DIRECTION_INBOUND
    Action = FW_ACTION_ALLOW
    Source port = 60692
    Dest port = 5355
    Ip protocol = 17
    Ethernet type = 0x800
    Process path = C:\WINDOWS\SYSTEM32\SVCHOST.EXE
    Local ip addr = 224.0.0.252
    Remote ip addr = XXX.XXX.240.150
    Source MAC = 00-00-00-00-00-00-00-00
    Dest MAC = 00-XX-e8-XX-36-XX-00-XX

Message was edited by: greatscott on 3/5/14 12:21:16 PM CST
2 Replies
Former Member
Not applicable
Report Inappropriate Content
Message 2 of 3

Re: Link Local Multicast Name Resolution v. HIPS Firewall et al

I am seeing this also.  Have you come up with a resolution yet?

Re: Link Local Multicast Name Resolution v. HIPS Firewall et al

I also have a HIPS Firewall Connection Aware Group (CAG) setup to activate by our internal DNS servers.  I have the following LLMNR rules setup and we've not experienced any issues, so far.  These rules took a lot of tuning after running things in Adaptive Mode for a few months.

2014-09-23 16_53_32-Greenshot.png

Good luck...

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from product experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by employees.
Join the Community
Join the Community