Firewall. EventId 5152 and 5157.<p align=left><font face=Arial size=2>In my security eventlog event with ID 5157 (The Windows Filtering Platform has blocked a connection) is always followed by event with id 5152 (The Windows Filtering Platform blocked a packet). What a difference between this events? Can I safely ignore the 5157 events when I design OpsMgr ACS reports?</font></p>© 2009 Microsoft Corporation. All rights reserved.Tue, 25 Aug 2009 17:01:47 Z9cb175a1-78fb-452e-b59d-0416940c2d20http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/9cb175a1-78fb-452e-b59d-0416940c2d20#9cb175a1-78fb-452e-b59d-0416940c2d20http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/9cb175a1-78fb-452e-b59d-0416940c2d20#9cb175a1-78fb-452e-b59d-0416940c2d20Alexey Zhuravlev - G14http://social.technet.microsoft.com/Profile/en-US/?user=Alexey%20Zhuravlev%20-%20G14Firewall. EventId 5152 and 5157.<p align=left><font face=Arial size=2>In my security eventlog event with ID 5157 (The Windows Filtering Platform has blocked a connection) is always followed by event with id 5152 (The Windows Filtering Platform blocked a packet). What a difference between this events? Can I safely ignore the 5157 events when I design OpsMgr ACS reports?</font></p>Tue, 01 Apr 2008 04:09:48 Z2008-04-08T10:44:34Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/9cb175a1-78fb-452e-b59d-0416940c2d20#26f3767a-6402-434d-938f-af59f1943bdchttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/9cb175a1-78fb-452e-b59d-0416940c2d20#26f3767a-6402-434d-938f-af59f1943bdcMiles Lihttp://social.technet.microsoft.com/Profile/en-US/?user=Miles%20LiFirewall. EventId 5152 and 5157.<font face=Arial size=2> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">Hi,</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'"> </span></p><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'"> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">ID       Message </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'"></span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">5152   The Windows Filtering Platform blocked a packet.  </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">5157   The Windows Filtering Platform has blocked a connection.  </span></p> <p class=MsoNormal style="margin:0in 0in 0pt" align=left></span> </p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">Event 5157 indicates that a connection (Transport layer) is blocked while Event 5152 indicates that a packet (IP layer) is blocked.</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">It is expected that system first logs the event of blocking a connection then the event of blocking a packet when a connection is restricted by a block rule. </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">For Event 5157 and  Event 5152 are general Windows Firewall security audit, you should look into the event detail of the blocked connection attempt to decide whether that attempt should be allowed. If the connection attempt is malicious or not necessary in your environment, you can safely ignore it.</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">Please try to check the detail to indentify the connection:</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">------------</span></p> <p><span style="font-size:9pt;font-family:'Verdana','sans-serif'">The Windows Filtering Platform has blocked a connection.</span></p> <p><span style="font-size:9pt;font-family:'Verdana','sans-serif'">Application Information:<br> Process ID:  <i>PID</i></span></p> <p><span style="font-size:9pt;font-family:'Verdana','sans-serif'"> Application Name: <i>process_name</i></span></p> <p><span style="font-size:9pt;font-family:'Verdana','sans-serif'">Network Information:<br> Direction:  <i>outbound or inbound</i><br> Source Address:  <i>source_ip</i></span></p> <p><span style="font-size:9pt;font-family:'Verdana','sans-serif'"> Source Port:   <br> Destination Address: <i>des_ip</i></span></p> <p><span style="font-size:9pt;font-family:'Verdana','sans-serif'"> Destination Port:  <br> Protocol:  </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">------------</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">By the way, just for your information, if you want to disable the security audit from the Windows Firewall, run '<i>auditpol.exe /set /SubCategory:&quot;MPSSVC rule-level Policy Change&quot;,&quot;Filtering Platform policy change&quot;,&quot;IPsec Main Mode&quot;,&quot;IPsec Quick Mode&quot;,&quot;IPsec Extended Mode&quot;,&quot;IPsec Driver&quot;,&quot;Other System Events&quot;,&quot;Filtering Platform Packet Drop&quot;,&quot;Filtering Platform Connection&quot; /success<img alt="Big Smile" src="http://forums.microsoft.com/MSDN/emoticons/emotion-2.gif">isable /failure<img height=19 alt="Big Smile" src="http://forums.microsoft.com/MSDN/emoticons/emotion-2.gif" width=19>isable</i>' in the command prompt.</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">More information about Windows Firewall feature in Windows Server 2008</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'"><a title="http://technet2.microsoft.com/windowsserver2008/en/library/c042b3c5-dee1-4a31-ac35-e90e846290441033.mspx" href="http://technet2.microsoft.com/windowsserver2008/en/library/c042b3c5-dee1-4a31-ac35-e90e846290441033.mspx"><font color="#800080">http://technet2.microsoft.com/windowsserver2008/en/library/c042b3c5-dee1-4a31-ac35-e90e846290441033.mspx</font></a></span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">Hope it helps.</span></p> <p align=left></font> </p>Wed, 02 Apr 2008 08:45:06 Z2008-04-02T08:45:06Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/9cb175a1-78fb-452e-b59d-0416940c2d20#52ca8398-0796-4bd7-b2b9-2af1d1ccf2a9http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/9cb175a1-78fb-452e-b59d-0416940c2d20#52ca8398-0796-4bd7-b2b9-2af1d1ccf2a9Alexey Zhuravlev - G14http://social.technet.microsoft.com/Profile/en-US/?user=Alexey%20Zhuravlev%20-%20G14Firewall. EventId 5152 and 5157.<p>Thank you Miles.</p> <p align=left> <blockquote> <table width="85%"> <tbody> <tr> <td class=quoteTable> <table width="100%"> <tbody> <tr> <td class=txt4 valign=top width="100%"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">Please try to check the detail to indentify the connection</span></td></tr></tbody></table></td></tr></tbody></table></blockquote>   <p></p> <p align=left>Of course I did. I can't understand this:</p> <p align=left>First (and most important):</p> <p align=left>In the &quot;<font face=Verdana>Protocol:</font>&quot; field of event I see UDP or ICMP protocol numbers. In <em>both</em> (5152 and 5157) events. ICMP can establish a connection?</p> <p align=left>Second:</p> <p align=left>Can you block a connection and dont drop a corresponding packets? Can you drop a packets and dont break a corresponding connection? Why we need 2 different events?</p> <p align=left><font face=Arial></font> </p>Wed, 02 Apr 2008 12:53:49 Z2008-04-02T12:53:49Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/9cb175a1-78fb-452e-b59d-0416940c2d20#5132838c-e3da-4cd7-a354-95178d7cd2c5http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/9cb175a1-78fb-452e-b59d-0416940c2d20#5132838c-e3da-4cd7-a354-95178d7cd2c5Miles Lihttp://social.technet.microsoft.com/Profile/en-US/?user=Miles%20LiFirewall. EventId 5152 and 5157.<p align=left><font face=Arial size=2></font> </p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">Hi,</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">It is not so accurate in my last post.</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">&quot;Event 5157 indicates that a connection (Transport layer) is blocked while Event 5152 indicates that a packet (IP layer) is blocked.&quot;</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">The meaning of the word 'connection' in Event 5157 is not the same as the connection in OSI model transport layer.</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">There are three kinds of flows that are defined as CONNECTION:</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><s><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'"><span style="text-decoration:none"></span></span></s> </p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">TCP ALE Flow</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">UDP ALE Flow (Protocols that are not TCP or ICMP are treated like UDP.)</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">ICMP ALE Flow</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">As UDP and ICMP are not connection-oriented protocols, the request and echo flows are defined as pseudo-connections here. In this case, WFP is dropping an ICMP packet and blocking a pseudo-connection (a request and echo flow) at the same time.</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">So, this should be expected.</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">For more information about ALE Filtering:</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">Application Layer Enforcement (ALE) Stateful Filtering</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'"><a title="http://msdn2.microsoft.com/en-us/library/bb613463(VS.85).aspx" href="http://msdn2.microsoft.com/en-us/library/bb613463(VS.85).aspx"><span style="color:#1f497d">http://msdn2.microsoft.com/en-us/library/bb613463(VS.85).aspx</span></a></span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Verdana','sans-serif'">Hope it helps.</span></p>Tue, 08 Apr 2008 05:31:20 Z2008-04-08T10:44:34Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/9cb175a1-78fb-452e-b59d-0416940c2d20#63a7801a-c2c4-4d55-a383-9a7fc3933b41http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/9cb175a1-78fb-452e-b59d-0416940c2d20#63a7801a-c2c4-4d55-a383-9a7fc3933b41Proginthttp://social.technet.microsoft.com/Profile/en-US/?user=ProgintFirewall. EventId 5152 and 5157.<p>I have searched all over the forums and websites, pulled out my propellor after installing hotfixes and I cannot get these event id's to go away on a Windows 2000 Server, any ideas?<br/><br/>Event Type: Error<br/>Event Source: Perflib<br/>Event Category: None<br/>Event ID: 1015<br/>Date:  24.Aug.09<br/>Time:  20:42:00<br/>User:  N/A<br/>Computer: PISERVER<br/>Description:<br/>The timeout waiting for the performance data collection function &quot;PerfDisk&quot; in the &quot;C:\WINNT\system32\perfdisk.dll&quot; Library to finish has expired. There may be a problem with  this extensible counter or the service it is collecting data from or the  system may have been very busy when this call was attempted. </p> <p> </p> <p><br/>Event Type: Warning<br/>Event Source: MRxSmb<br/>Event Category: None<br/>Event ID: 3034<br/>Date:  25.Aug.09<br/>Time:  09:33:44<br/>User:  N/A<br/>Computer: PISERVER<br/>Description:<br/>The redirector was unable to initialize security context or query context attributes. <br/>Data:<br/>0000: 00 00 08 00 02 00 56 00   ......V.<br/>0008: 00 00 00 00 da 0b 00 80   ....Ú..&#128;<br/>0010: 00 00 00 00 5f 00 00 c0   ...._..À<br/>0018: 00 00 00 00 00 00 00 00   ........<br/>0020: 00 00 00 00 00 00 00 00   ........<br/>0028: f3 04 00 00 5f 00 00 c0   ó..._..À</p><hr class="sig">eph61820Tue, 25 Aug 2009 17:01:46 Z2009-08-25T17:01:46Z