EnvisaLink try to connect externally without permission
Posted: Thu Apr 20, 2017 8:35 am
Hi
I have had the Envisalink card connected to eye-zone earlier. Now I have removed my account due to that I want to run it all local. But in my FW I can see that the EnvisaLink tries to connect externally over and over again to 198.61.170.85, so I had to block the outgoing traffic in my firewall. The card is very aggressive in its try to connect.... And this goes on forever.
WHY do this happen? What do I do to make it stop?
root@xanadu:/etc#tcpdump -e -n -ttt -r /var/log/pflog|grep 4021|tail -9
tcpdump: WARNING: snaplen raised from 116 to 160
Apr 20 14:27:23.538669 rule 214/(match) block in on vlan2: 192.168.0.187.7733 > 198.61.170.85.4021: udp 256
Apr 20 14:27:59.637932 rule 214/(match) block in on vlan2: 192.168.0.187.7734 > 198.61.170.85.4021: udp 256
Apr 20 14:28:20.195554 rule 214/(match) block in on vlan2: 192.168.0.187.7734 > 198.61.170.85.4021: udp 256
Apr 20 14:28:56.295269 rule 214/(match) block in on vlan2: 192.168.0.187.7735 > 198.61.170.85.4021: udp 256
Apr 20 14:29:16.352291 rule 214/(match) block in on vlan2: 192.168.0.187.7735 > 198.61.170.85.4021: udp 256
Apr 20 14:29:52.454572 rule 214/(match) block in on vlan2: 192.168.0.187.7736 > 198.61.170.85.4021: udp 256
Apr 20 14:30:12.511152 rule 214/(match) block in on vlan2: 192.168.0.187.7736 > 198.61.170.85.4021: udp 256
Apr 20 14:30:49.616397 rule 214/(match) block in on vlan2: 192.168.0.187.7737 > 198.61.170.85.4021: udp 256
Apr 20 14:31:10.675753 rule 214/(match) block in on vlan2: 192.168.0.187.7737 > 198.61.170.85.4021: udp 256
Thanks
Peo
I have had the Envisalink card connected to eye-zone earlier. Now I have removed my account due to that I want to run it all local. But in my FW I can see that the EnvisaLink tries to connect externally over and over again to 198.61.170.85, so I had to block the outgoing traffic in my firewall. The card is very aggressive in its try to connect.... And this goes on forever.
WHY do this happen? What do I do to make it stop?
root@xanadu:/etc#tcpdump -e -n -ttt -r /var/log/pflog|grep 4021|tail -9
tcpdump: WARNING: snaplen raised from 116 to 160
Apr 20 14:27:23.538669 rule 214/(match) block in on vlan2: 192.168.0.187.7733 > 198.61.170.85.4021: udp 256
Apr 20 14:27:59.637932 rule 214/(match) block in on vlan2: 192.168.0.187.7734 > 198.61.170.85.4021: udp 256
Apr 20 14:28:20.195554 rule 214/(match) block in on vlan2: 192.168.0.187.7734 > 198.61.170.85.4021: udp 256
Apr 20 14:28:56.295269 rule 214/(match) block in on vlan2: 192.168.0.187.7735 > 198.61.170.85.4021: udp 256
Apr 20 14:29:16.352291 rule 214/(match) block in on vlan2: 192.168.0.187.7735 > 198.61.170.85.4021: udp 256
Apr 20 14:29:52.454572 rule 214/(match) block in on vlan2: 192.168.0.187.7736 > 198.61.170.85.4021: udp 256
Apr 20 14:30:12.511152 rule 214/(match) block in on vlan2: 192.168.0.187.7736 > 198.61.170.85.4021: udp 256
Apr 20 14:30:49.616397 rule 214/(match) block in on vlan2: 192.168.0.187.7737 > 198.61.170.85.4021: udp 256
Apr 20 14:31:10.675753 rule 214/(match) block in on vlan2: 192.168.0.187.7737 > 198.61.170.85.4021: udp 256
Thanks
Peo