Thanks &Regards Amanda Wang[MSFT] Microsoft Online Partner Support Get Secure! - www.microsoft.com/security ==================================================================== When responding to posts, please "Reply to Group" via your newsreader so that others may learn and benefit Not to mention there isn't even traffic for this, it's just listening for connections. –Chris Marisic Aug 27 '09 at 19:50 add a comment| 1 Answer 1 active oldest votes up Question has a verified solution. Sign up now! this contact form
Windows XP uses the same service for the firewall and for the Internet Connection Sharing as well. The only solution to eliminate this event flood was to switched off the "Audit Process Tracking" audit policy in the domain. Stopping and disabling this service means the ICS will not operate at all. The port is random. >> >> I'm actually using Norton Internet Security 2009, which may have it's own >> firewall. >> >> What's the best way to handle it? >> >>
It appears over and over again, filling up the logs. Event ID 861 Source Securit http://www.eventid.net/display.asp?eventid=861&eventno=4615&source=Security&phase=1 Transcript: Windows XP SP2: Windows Firewall http://www.microsoft.com/windowsxp/expertzone/chats/transcripts/05_jan12_win_fw.mspx browse down to one of Jo_MS answeres Troubleshooting Windows Firewall in Microsoft Windows XP Service Pack http://www.microsoft.com/downloads/...46-131d-4617-bf68-f0532d8db131&displaylang=en download Please see my other post. If your security auditing policy includes auditing of failures for "audit process tracking", your security event logs will be filling up quickly.
Marked as answer by David Shen Wednesday, June 24, 2009 2:12 AM Tuesday, June 23, 2009 6:31 AM Reply | Quote 0 Sign in to vote Hi David, Thank you for There is an easy way to manage all of these requests... Not related to power supply... All Rights Reserved Tom's Hardware Guide ™ Ad choices MenuExperts Exchange Browse BackBrowse Topics Open Questions Open Projects Solutions Members Articles Videos Courses Contribute Products BackProducts Gigs Live Courses Vendor Services
The NETWORK SERVICE event happens every 1 - 5 minutes. The Windows Firewall Has Detected An Application Listening For Incoming Traffic Lsass Exe The other reason is on another work station in our domain this occured from the time the pc was unboxed from dell. If you are clean, then determine if the listening process is valid for the host. Under admin tools, launch 'local security policy', navigate to local policies\audit policy, and set it up for no auditing.
Name: - Path: C:\WINDOWS\system32\lsass.exe Process identifier: 1348 User account: SYSTEM User domain: NT AUTHORITY Service: Yes RPC server: No IP version: IPv4 IP protocol: UDP Port number: 1352 Allowed: No User If you want the events to go away, the only solutions I have found so far are to turn off the auditing or to stop the Windows Firewall/ICS service. ERROR The requested URL could not be retrieved The following error was encountered while trying to retrieve the URL: http://0.0.0.1/ Connection to 0.0.0.1 failed. Hutchings, Sep 14, 2009 #4 Advertisements Show Ignored Content Want to reply to this thread or ask your own question?
The error message begins filling up the security log the instant I join the computer to the domain. If you are experiencing a similar issue, please ask a related question Suggested Solutions Title # Comments Views Activity Subnetting: Network with six subnets 8 113 112d Publishing App's on Terminal Event Id 861 Windows Firewall Join the community of 500,000 technology professionals and ask your questions. Generated Thu, 29 Dec 2016 06:56:01 GMT by s_wx1077 (squid/3.5.20) TechNet Products IT Resources Downloads Training Support Products Windows Windows Server System Center Browser Office Office 365 Exchange Server
Not the answer you're looking for? weblink Custom search for *****: Google - Bing - Microsoft - Yahoo Feedback: Send comments or solutions - Notify me when updated Printer friendly Subscribe Subscribe to EventID.Net now!Already a subscriber? I'd like to keep the XP firewall turned on, if possible. Name: - Path: C:\WINDOWS\system32\lsass.exe Process identifier: 428 User account: SYSTEM User domain: NT AUTHORITY Service: Yes RPC server: No IP version: IPv4 IP protocol: UDP Port number: 4500 Allowed: Yes User
Name: - Path: C:\WINDOWS\system32\svchost.exe Process identifier: 748 User account: NETWORK SERVICE User domain: NT AUTHORITY Service: Yes RPC server: No IP version: IPv4 IP protocol: UDP Port number: 64697 Allowed: No Covered by US Patent. It is almost like there is a port scanning bug on the server trying to find open ports or something. navigate here Marked as answer by David Shen Friday, June 19, 2009 11:37 AM Edited by David Shen Tuesday, June 23, 2009 6:13 AM Friday, June 19, 2009 4:23 AM Reply | Quote
The security logs on some of my networks client machines (all Windows Xp Sp3) get filled with these useless error messages. Event ID 56 Volmgr Event ID 46 solved Kernel Power Event ID 41 Task 63 No Solution yet solved Kernel-power, event ID 41 solved event id 41 error after restoring an The Firewall/ICS service can be run even if the firewall is switched off by the appropriate Control Panel applet.
The port is random. > > I'm actually using Norton Internet Security 2009, which may have it's own > firewall. > > What's the best way to handle it? > > Math / Science Solar Technology How OnPage integrates into ConnectWise Video by: Adam C. These security log entries are viewed with Event Viewer, which can filter the entries by Event IDs. Is a "object constructor" a shorter name for a "function with name `object` returning type `object`"?
If there is anything unclear or any other questions about this issue, please feel free to let me know. Frederick R. Subscribe to our monthly newsletter for tech news and trends Membership How it Works Gigs Live Careers Plans and Pricing For Business Become an Expert Resource Center About Us Who We his comment is here How does the FAA determine which format of location identifier to assign to an airport?
I know its not a trojan or virus, these are brand new machines. Microsoft Customer Support Microsoft Community Forums Windows Server TechCenter Sign in United States (English) Brasil (Português)Česká republika (Čeština)Deutschland (Deutsch)España (Español)France (Français)Indonesia (Bahasa)Italia (Italiano)România (Română)Türkiye (Türkçe)Россия (Русский)ישראל (עברית)المملكة العربية السعودية (العربية)ไทย (ไทย)대한민국