I have a user with a strange traffic consumption. At which I need Drop..
I see in torch.. udp, ip source, ip destination and traffic, but the port fields appears in blank.
I assumed that is the ZERO UDP port. And I put some rules in firewall filter.. For to drop this port.. but the firewall no drop this traffic. What is this??
Questions:
1- How I do for drop this traffic.??
2- For what reason don’t appears the ports in torch.??
I observe ip destination, change periodically.. aleatory..
My question is how configure the firewall filter: If a connection use source udp port blank and destination udp port blank, I NEED drop this traffic..???
Two data is equal all time: ip source ( client) and protocol udp. And ports in blank..