While investigating some internet bandwidth issues, I came across a bunch of UDP packets flooding my broadband. The message is:
Jul 13 14:37:33
IPTABLES UDP-FLOOD: IN=vlan1 OUT= MAC=ec:1a:59:47:1a:a1:00:17:10:8a:12:15:08:00:45:00:00:b0:00:00:40:00:38:11:6b:22:c6:99 SRC=198.153.192.120 DST=My.WAN.IP LEN=176 TOS=00 PREC=0x00 TTL=56 ID=0 DF PROTO=UDP SPT=53 DPT
where "My.Wan.IP" is my actuall IP address from my provider. The link is broadband and the router is a Belkin.
When I looked up the source address, I learn that it is owned by Symantec:
Source: whois.arin.net
IP Address: 198.153.192.120 (United States)
Name: NETBLK-OPENVISION
Handle: NET-198-153-190-0-1
Registration Date: 8/11/93
Range: 198.153.190.0-198.153.196.255
Org: Symantec Corporation
Org Handle: SYMN-Z
Address: 350 Ellis St.
City: Mountain View
State/Province: CA
Postal Code: 95117
Country: UNITED STATES
I have one computer on my internal network that runs Norton's AV which is the only Symantec product I have so I assume that the constant UDP flood has to do with Noron's AV. So my question is, what is the UDP flood about and how do I get it to stop? I assume there must be something in Norton's that Symantec is trying to reach. Any help would be appreciated.
Thanks.