Unusual message from firewall

Posted: 07-22-2003, 11:55 PM
While downloading some Usenet articles from the Ney on my XP Pro
system, I got the following message from my Sygate Pro firewall
(version 5.0).


--- QUOTE ----

LSA Shell [Export Version] is being connected by the remote machine
[80.116.234.103] using local port 500 (ISAKMP - Internet Security
Association and Key Management/IPSEC Key Exchange). Do you want to
allow this program to access the network?

C\WINDOWS\SYSTEM32\LSASS.EXE

--- END QUOTE ----


What was trying to access the net through the firewall? Was it
legit? Was it spyware?

Thanks for any info.

Reply With Quote

Responses to "Unusual message from firewall"

CS
Guest
Posts: n/a
 
Re: Unusual message from firewall
Posted: 07-23-2003, 01:20 AM
On Tue, 22 Jul 2003 23:55:55 +0100, Vance Roos <not__me@mail.com>
wrote:

I have no idea what it was - but when Sygate warns of some program
which is unfamiliar to me, I just say no. Don't worry about it, it
may have been something legitimate, but why take chances?
>While downloading some Usenet articles from the Ney on my XP Pro
>system, I got the following message from my Sygate Pro firewall
>(version 5.0).
>
>
>--- QUOTE ----
>
>LSA Shell [Export Version] is being connected by the remote machine
>[80.116.234.103] using local port 500 (ISAKMP - Internet Security
>Association and Key Management/IPSEC Key Exchange). Do you want to
>allow this program to access the network?
>
>C\WINDOWS\SYSTEM32\LSASS.EXE
>
>--- END QUOTE ----
>
>
>What was trying to access the net through the firewall? Was it
>legit? Was it spyware?
>
>Thanks for any info.
Reply With Quote
Walter Roberson
Guest
Posts: n/a
 
Re: Unusual message from firewall
Posted: 07-23-2003, 02:05 AM
In article <93C0F3733AE7A471AE@130.133.1.4>,
Vance Roos <not__me@mail.com> wrote:
:While downloading some Usenet articles from the Ney on my XP Pro
:system, I got the following message from my Sygate Pro firewall

:LSA Shell [Export Version] is being connected by the remote machine
:[80.116.234.103] using local port 500 (ISAKMP - Internet Security
:Association and Key Management/IPSEC Key Exchange).

Notice it says it is being contacted by a remote machine. The implication
is that while you *happened* to be doing <whatever>, someone/something at
80.116.234.103 probed your udp 500 port. The attempted access probably
had nothing to do with any activity of yours.

:What was trying to access the net through the firewall? Was it
:legit? Was it spyware?

% This is the RIPE Whois server.
inetnum: 80.116.128.0 - 80.116.255.255
netname: TINIT-ADSL-LITE
descr: Telecom Italia

Unless you happen to have been accessing a slow-speed ADSL (512 Kb max
upload speed) based host in Italy, chances are good that the
access attempt Should Not Have Happened.
--
IEA408I: GETMAIN cannot provide buffer for WATLIB.
Reply With Quote
Bjorn Randell
Guest
Posts: n/a
 
Re: Unusual message from firewall
Posted: 07-23-2003, 11:01 PM
"Vance Roos" <not__me@mail.com> wrote in message
news:93C0F3733AE7A471AE@130.133.1.4...
> While downloading some Usenet articles from the Ney on my XP Pro
> system, I got the following message from my Sygate Pro firewall
> (version 5.0).
>
>
> --- QUOTE ----
>
> LSA Shell [Export Version] is being connected by the remote machine
> [80.116.234.103] using local port 500 (ISAKMP - Internet Security
> Association and Key Management/IPSEC Key Exchange). Do you want to
> allow this program to access the network?
>
> C\WINDOWS\SYSTEM32\LSASS.EXE
>
> --- END QUOTE ----
>
>
> What was trying to access the net through the firewall? Was it
> legit? Was it spyware?
It was legit, no spyware. Type EXEs name into Google for proof.

The remote machine was trying to see if you would like to talk to it in an
IPSEC encrypted fashion. Check your local security policy and turn off
client-respond if you don't want this to happen in future.

--
Regards,
Bjorn Randell
Bjorn@AlphaMale.me.uk or ICQ #137732


Reply With Quote
Vance Roos
Guest
Posts: n/a
 
Re: Unusual message from firewall
Posted: 07-24-2003, 08:28 AM
"Bjorn Randell" <Bjorn@AlphaMale.me.uk> wrote:
> "Vance Roos" <not__me@mail.com> wrote in message
> news:93C0F3733AE7A471AE@130.133.1.4...
>> While downloading some Usenet articles from the Ney on my XP
>> Pro system, I got the following message from my Sygate Pro
>> firewall (version 5.0).
>>
>>
>> --- QUOTE ----
>>
>> LSA Shell [Export Version] is being connected by the remote
>> machine [80.116.234.103] using local port 500 (ISAKMP -
>> Internet Security Association and Key Management/IPSEC Key
>> Exchange). Do you want to allow this program to access the
>> network?
>>
>> C\WINDOWS\SYSTEM32\LSASS.EXE
>>
>> --- END QUOTE ----
>>
>>
>> What was trying to access the net through the firewall? Was it
>> legit?
>> Was it spyware?
>
> It was legit, no spyware. Type EXEs name into Google for proof.
>
> The remote machine was trying to see if you would like to talk
> to it in an IPSEC encrypted fashion. Check your local security
> policy and turn off client-respond if you don't want this to
> happen in future.

Do I lose any functionality if I do turn it off as you suggest?
Reply With Quote
 
LinkBack Thread Tools Display Modes
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Very unusual print problem web-dept Windows Vista Printers & Scanners 0 02-07-2007 01:43 AM
xp firewall error message Cliff Customize Windows XP 4 10-05-2003 03:13 PM
Unusual Folder names Brian Elkins Windows XP Basics 0 09-25-2003 02:39 PM
error message when activating xp's firewall eric Windows XP Security & Administration 3 08-20-2003 10:34 AM
unusual pop ups mike Windows XP 1 07-14-2003 04:35 PM


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90