CS12: customer DC found a large number of Event 5152 logs and asked for help to troubleshoot the cause
Summary of customer questions:
The customer said that a large number of security logs with an ID of 5152 were found on the domain control, almost 3 per second, and they wanted to give relevant checks.
The log is as follows:
The Windows Filtering Platform has blocked a packet.
Application Information:
Process ID: 0
Application Name:-
Network Information:
Direction: Inbound
Source Address: 0.0.0.0
Source Port: 68
Destination Address: 255.255.255.255
Destination Port: 67
Protocol: 17
Filter Information:
Filter Run-Time ID: 437032
Layer Name: Transport
Layer Run-Time ID: 13
Solution:
And WFP filtering logs are enabled by the customer. Just turn off this logging.
For example:
Close this log using the following command:
Auditpol / set / category: "system" / subCategory: "Filtering Platform Connection" / Failure:Disable
Auditpol / set / category: "system" / subCategory: "Filtering Platform Packet Drop" / Failure:Disable
Then gpupdate / force refreshes the group policy