abnormal udp traffic detected, source port is zero, DROP (port53)
Options
All Replies
-
So its blocked what are you trying to do? stop it logging the block?0
-
yep,
I dont know why I'm alerted if my port is closed (and Log denied traffic is set to no)
0 -
Its logging due to it being set in security policy > ADP > profile tab
0 -
Hi @ktv
Those logs were generated by UDP abnormal traffic protection of ADP.
So, even you disable DNS UDP port 53 session on security policy, those similar log messages still can be seen.
If you don’t want to see them you may navigate Configuration > Security Policy > ADP and set "Traffic Anomaly", "Protocol Anomaly" Log to “no”.
Hope this can help you.

0
Categories
- All Categories
- 439 Beta Program
- 2.8K Nebula
- 207 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.4K Security
- 528 USG FLEX H Series
- 330 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.3K Wireless
- 49 Wireless Ideas
- 6.9K Consumer Product
- 290 Service & License
- 462 News and Release
- 90 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.6K FAQ
- 34 Documents
- 86 About Community
- 99 Security Highlight
Freshman Member



Guru Member
Zyxel Employee
