Skip to content
DnsLister Forum

Where domain hunters compare notes

Why is mDNS traffic from the gateway getting flagged by IDS (port 5353)?

Who can explain why my gateway is flagging this traffic and is blocking it. I know it's to mdns.mcast.net on 5353 (mDNS), but what's going on here? Isn't this "normal" mDNS traffic?

A network intrusion attempt from 192.168.10.1 to 224.0.0.251 has been detected and blocked. Risk High Verdict Blocked Signature ET P2P eMule KAD Network Firewalled Request Category emerging-p2p Signature ID 2009969 This indicates potential use of applications that may not be appropriate for corporate environments. This is usually more acceptable for home environments. Counterpart 224.0.0.251 Date / Time Aug 4, 2026 at 3:21 AM Source MAC xxxxxxxxxx Source IP 192.168.10.1 Source Port 55843 Destination IP 224.0.0.251 Destination Port 5353 Protocol UDP Total Data 633 bytes Packets Sent 7 Packets Received 0 Bytes Sent 633 bytes Bytes Received 0 bytes 

submitted by /u/AliasJackBauer to r/Ubiquiti
[link] [comments]

Source: r/Ubiquiti · by /u/AliasJackBauer

Leave a Reply

Your email address will not be published. Required fields are marked *