F5F Stay Refreshed Software Operating Systems Numerous occurrences involving 5156 and 5152

Numerous occurrences involving 5156 and 5152

Numerous occurrences involving 5156 and 5152

J
Jarvan_IV
Member
120
05-02-2023, 03:50 AM
#1
You're seeing a high volume of events—around 20,000 per hour for both 5156 and 5152. That's quite intense. It could be normal if your torrent client is generating a lot of data, but it might also indicate excessive logging or misconfigurations. Your firewall, especially TinyWall, may be triggering many alerts due to its strict filtering rules. Check if the events are legitimate or if you can adjust the firewall settings to reduce noise.
J
Jarvan_IV
05-02-2023, 03:50 AM #1

You're seeing a high volume of events—around 20,000 per hour for both 5156 and 5152. That's quite intense. It could be normal if your torrent client is generating a lot of data, but it might also indicate excessive logging or misconfigurations. Your firewall, especially TinyWall, may be triggering many alerts due to its strict filtering rules. Check if the events are legitimate or if you can adjust the firewall settings to reduce noise.

P
PatrickJosh
Member
109
05-09-2023, 07:53 AM
#2
From Microsoft ID Message. 5152 The Windows Filtering Platform intercepted a packet. Event 5152 shows a blocked packet at the IP layer. Events 5157 and 5152 relate to general Windows Firewall security checks; examine the blocked connection details to determine if it should be permitted. 5156 The Windows Filtering Platform has granted a connection. This log records each instance where WFP permits a program to link with another process (on the same or distant machine) via TCP or UDP port. The provided scenario illustrates WFP enabling a DNS Server service to connect with its client on the same system.
P
PatrickJosh
05-09-2023, 07:53 AM #2

From Microsoft ID Message. 5152 The Windows Filtering Platform intercepted a packet. Event 5152 shows a blocked packet at the IP layer. Events 5157 and 5152 relate to general Windows Firewall security checks; examine the blocked connection details to determine if it should be permitted. 5156 The Windows Filtering Platform has granted a connection. This log records each instance where WFP permits a program to link with another process (on the same or distant machine) via TCP or UDP port. The provided scenario illustrates WFP enabling a DNS Server service to connect with its client on the same system.

W
Winnerr
Member
69
05-10-2023, 06:20 AM
#3
I understand what you're referring to. Just wanted to confirm if they were meant to be there. In the meantime, I tried running Windows on a VM and those events didn't appear, suggesting they weren't intended for auditing. It's likely they were added by a Comodo firewall long ago. When I executed "auditpol /clear" in the command prompt, the issue resolved, and my firewall appears to be functioning properly.
W
Winnerr
05-10-2023, 06:20 AM #3

I understand what you're referring to. Just wanted to confirm if they were meant to be there. In the meantime, I tried running Windows on a VM and those events didn't appear, suggesting they weren't intended for auditing. It's likely they were added by a Comodo firewall long ago. When I executed "auditpol /clear" in the command prompt, the issue resolved, and my firewall appears to be functioning properly.

M
MacSolaris
Senior Member
457
05-16-2023, 09:48 PM
#4
They are meant to be present, allowing MS to analyze the data and determine how to exploit it in future updates. On a perfect day, we can do both!
M
MacSolaris
05-16-2023, 09:48 PM #4

They are meant to be present, allowing MS to analyze the data and determine how to exploit it in future updates. On a perfect day, we can do both!

B
BlooPancake
Junior Member
48
05-17-2023, 01:48 AM
#5
It seems you're questioning the functionality of the "auditpol /clear" command. It actually disables recording rather than resetting it, which might explain why you didn't notice any changes. I wonder how often the event viewer has assisted you in the past?
B
BlooPancake
05-17-2023, 01:48 AM #5

It seems you're questioning the functionality of the "auditpol /clear" command. It actually disables recording rather than resetting it, which might explain why you didn't notice any changes. I wonder how often the event viewer has assisted you in the past?