Who can explain why my gateway is flagging this traffic and is blocking it. I know it's to mdns.mcast.net on 5353 (mDNS), but what's going on here? Isn't this "normal" mDNS traffic?
A network intrusion attempt from 192.168.10.1 to 224.0.0.251 has been detected and blocked. Risk High Verdict Blocked Signature ET P2P eMule KAD Network Firewalled Request Category emerging-p2p Signature ID 2009969 This indicates potential use of applications that may not be appropriate for corporate environments. This is usually more acceptable for home environments. Counterpart 224.0.0.251 Date / Time Aug 4, 2026 at 3:21 AM Source MAC xxxxxxxxxx Source IP 192.168.10.1 Source Port 55843 Destination IP 224.0.0.251 Destination Port 5353 Protocol UDP Total Data 633 bytes Packets Sent 7 Packets Received 0 Bytes Sent 633 bytes Bytes Received 0 bytes
submitted by /u/AliasJackBauer to r/Ubiquiti
[link] [comments]
Source: r/Ubiquiti · by /u/AliasJackBauer