• 所有社区 - 中文
    • 所有社区 - 中文
    • 论坛
    • 创意
    • 博客
高级

不是您要找的? 咨询专家!

此论坛帖文需要解决方案。
好评0

Norton VPN (part of 360) keeps trying to reach out to external IPs on port 80

My network hardware firewall (and my SIEM) keep reporting that my various Norton360/VPN installations keep sending SYN packets to addresses within my ISP's IP range. This is happening once every few seconds or so and it is constantly on. Why is this happening? Why would Norton do this? It doesn't make sense to me.

Example:

From the firewall logs with only one of the sources selected:

23:05:22 Default DROP TCP 192.168.1.170:58087 62.253.3.178:80 [SYN] len=52ttl=127tos=0x00
23:05:26 Default DROP TCP 192.168.1.170:58096 62.253.3.179:80 [SYN] len=52ttl=127tos=0x00
23:05:27 Default DROP TCP 192.168.1.170:58096 62.253.3.179:80 [SYN] len=52ttl=127tos=0x00
23:05:29 Default DROP TCP 192.168.1.170:58096 62.253.3.179:80 [SYN] len=52ttl=127tos=0x00
23:05:32 Default DROP TCP 192.168.1.170:58096 62.253.3.179:80 [SYN] len=52ttl=127tos=0x00
23:05:46 Default DROP TCP 192.168.1.170:58099 62.253.3.179:80 [SYN] len=52ttl=127tos=0x00
23:05:47 Default DROP TCP 192.168.1.170:58099 62.253.3.179:80 [SYN] len=52ttl=127tos=0x00
23:05:48 Default DROP TCP 192.168.1.170:58099 62.253.3.179:80 [SYN] len=52ttl=127tos=0x00
23:05:53 Default DROP TCP 192.168.1.170:5809962.253.3.179:80 [SYN] len=52ttl=127tos=0x00

From netstat executed on the machine at 192.168.1.170 at 23:05:48:

 TCP    192.168.1.170:58099    179.3-253-62.static.virginmediabusiness.co.uk:http  SYN_SENT        11224
 [Norton Secure VPN.exe]

62.253.3.17[89] are not my IPs and 11224 was indeed the Norton VPN PID. All Norton is running on win10 1903.

Any ideas why this would be happening and how can i make it stop? I do not have Norton VPN set up so it shouldn't be doing anything inmho. It is filling my logs, it is scaring my SIEM and FW and it is annoying me :D

thanks!