problem with control application

I have a user with a strange traffic consumption. At which I need Drop..

I see in torch.. udp, ip source, ip destination and traffic, but the port fields appears in blank.

I assumed that is the ZERO UDP port. And I put some rules in firewall filter.. For to drop this port.. but the firewall no drop this traffic. What is this??

Questions:
1- How I do for drop this traffic.??
2- For what reason don’t appears the ports in torch.??

Help…

maybe drop by destination IP ?

Hi,

I observe ip destination, change periodically.. aleatory..
My question is how configure the firewall filter: If a connection use source udp port blank and destination udp port blank, I NEED drop this traffic..???

Two data is equal all time: ip source ( client) and protocol udp. And ports in blank..

THANK

use “!” - “not” notation - drop all UDP except those that have port