Audit failure alerts -- what to do

dale5351

New member
Member
Local time
5:16 PM
Messages
74
Location
Columbia, MD
(not sure if this is the correct sub-forum -- if not, please point me to a better one).

I am getting consistent frequent messages in my event viewer about
The Windows Filtering Platform has blocked a connection.
Further down, it says "audit failure".
The current set of messages is from ap name = system, inbound, source address 224.0.0.1 to destination address of 192.168.1.1 (which is my Verizon router).

My questions are:
1. is this an indication of some sort of problem?
2. how do I stop the message from flooding my event log (currently occuring about every 9 minutes).
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
DELL xps8500
OS
Microsoft Windows 7 Professional 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i7-3770 CPU @ 3.40GHz
Motherboard
Dell Inc. 0NW73C
Memory
16.00 GB
Graphics Card(s)
NVIDIA GeForce GT 620
Sound Card
(1) NVIDIA High Definition Audio (2) Realtek High Definiti
Screen Resolution
1280 x 1024 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
(1) WDC WD10EZEX-75ZF5A0 (2) Generic- Compact Flash USB Device (3) Generic- MS/MS-Pro USB Device (4) Generic- SD/MMC USB Device (5) Generic- SM/xD-Picture USB Device (6) WD My Passport 0820 USB Device
Hi Dale,

It would depend on whether your Firewall is part of your AV suite, or the standard MS built-in.

What is the event ID 5152/5157?


Roy
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
medionl/Aspire 6930G/acer x55a
OS
W7 home premium 32bit/W7HP 64bit/w10 tp insider ring
CPU
E5300 dual core
Motherboard
medion MS7366
Memory
3gb
Graphics Card(s)
Nvidia Geforce 7100 Nforce 630i
Monitor(s) Displays
avixc
Internet Speed
n (isp resticted to 72)
Antivirus
mse/pands
Browser
palemoon
Other Info
Belkin Fd7050 n USB using Railink RT2870 drivers, more upto date
My firewall is standard Win firewall, virus suite is Avast free. The event ID is 5157.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
DELL xps8500
OS
Microsoft Windows 7 Professional 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i7-3770 CPU @ 3.40GHz
Motherboard
Dell Inc. 0NW73C
Memory
16.00 GB
Graphics Card(s)
NVIDIA GeForce GT 620
Sound Card
(1) NVIDIA High Definition Audio (2) Realtek High Definiti
Screen Resolution
1280 x 1024 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
(1) WDC WD10EZEX-75ZF5A0 (2) Generic- Compact Flash USB Device (3) Generic- MS/MS-Pro USB Device (4) Generic- SD/MMC USB Device (5) Generic- SM/xD-Picture USB Device (6) WD My Passport 0820 USB Device
Hi Dale,

heres a definition of the 224 0 0 1

A multicast address is a single IP data packet set that represents a network host group. Multicast addresses are available to process datagrams or frames intended to be multicast

in laymans terms - im, or trying, talking to another piece of equipement on your network
SO ITS ALL INTERNAL
nothing to worry about:)
note,
equipement can also mean a program that has been removed, including AV's, but not all the associated interactions have been.

Roy
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
medionl/Aspire 6930G/acer x55a
OS
W7 home premium 32bit/W7HP 64bit/w10 tp insider ring
CPU
E5300 dual core
Motherboard
medion MS7366
Memory
3gb
Graphics Card(s)
Nvidia Geforce 7100 Nforce 630i
Monitor(s) Displays
avixc
Internet Speed
n (isp resticted to 72)
Antivirus
mse/pands
Browser
palemoon
Other Info
Belkin Fd7050 n USB using Railink RT2870 drivers, more upto date
Back
Top