Security Incidents mailing list archives

Re: odd UDP source port 500 dst port 500 traffic


From: Rick Payne <rickp () ROSSFELL CO UK>
Date: Fri, 23 Mar 2001 13:46:44 -0000

--On Thursday, March 22, 2001 13:41:22 -0500 fire-eyes
<sgtphou () FIRE-EYES YI ORG> wrote:

Anyone know what this is? I wasn't able to toss a sniffer up on it.


Mar 22 13:35:42 fire-eyes iplog[389]: UDP: dgram to
tnt1a-111.flint.corecomm.net
 (216.214.82.111):port 500 from x.edu (x):500
(904 data bytes)

Its most likely ISAKMP - the IPsec key exchange protocol.

Rick


Current thread: