Hi...I have Kerio 4.1.3 PF and everything seems to be working fine. I am curious though about my logs which show a continuous (about three times per second) stream of UDP data. I haven't been able to find anything as to what this is and if anything needs to done. These are the details:
Description: Unopened Port Application: N/A Direction: In Local Point: 255.255.255.255:bootpc Remote Point: 10.117.198.1:bootpc Protocol: UDP Action: Permit
I tried opening the url 10.117.198.1 and got a "connection refused" flag. Looking up 10.117.198.1 on www.whois gives an organization located in Ca.,USA called "Internet Assigned Numbers Authority" (IANA) which apparently has a range of domains from 10.0.0.0 to 10.255.255.255 reserved "for special purposes". All of which only tells me the url is real and so is the organization sending me these UDP data to an unopened port. Is it for a legitimate purpose? If so what is it? Should I block 10.117.198.1 or the whole range of 10.0.0.0 to 10.255.255.255? Any info or pointer to a good reference site for reading would be appreciated. Regards, Nick