×
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Hayton
Reliable Contributor
Reliable Contributor
Message 1 of 2

"A computer at us.mcafee.com has attempted an unsolicited connection to port 1563.."

Jump to solution

I have Firewall Security Settings set to Stealth, so my Incoming Events log file has a lot of entries in it. Most can probably be ignored, but there is one I am not sure about.

Two days ago I noticed two entries in the log file showing an attempt by a computer with the source IP of 161.69.12.13 to connect to port 1563. I hadn't seen that entry in the log file before.

Port 1563 "is commonly used by the Cadabra License Manager service or program".  The IP resolves to a host name of "us.mcafee.com"; but, ever since the latest (2010) version arrived, I cannot use a Trace facility to verify from within the program that the IP identification is correct.

There are three other connection attempts from the same IP, to ports 1050 and 1087.

Why would McAfee be attempting to open those ports? And, if it is indeed McAfee, should I add the ports to the list in "Ports and System Services", or add this IP to the list of IPs in "Connections"? Or both, or neither?

Message was edited by: Hayton on 18/10/10 03:23:36 IST

Message was edited by: Hayton on 18/10/10 03:28:37 IST
1 Solution

Accepted Solutions
exbrit
MVP
MVP
Message 2 of 2

Re: "A computer at us.mcafee.com has attempted an unsolicited connection to port 1563.."

Jump to solution

I have no idea why they are looking at those ports but I would assume it's a normal update function.  I used Utrace and that IP is definitely McAfee.

I would consult with Technical Support Chat regarding what to do when you have the firewall in any non-standard configurations.

However if you are reading from the Inbound Events there is no need to do anything unless you get a popup asking for permission.

Message was edited by: Ex_Brit on 18/10/10 7:34:28 EDT AM

View solution in original post

1 Reply
exbrit
MVP
MVP
Message 2 of 2

Re: "A computer at us.mcafee.com has attempted an unsolicited connection to port 1563.."

Jump to solution

I have no idea why they are looking at those ports but I would assume it's a normal update function.  I used Utrace and that IP is definitely McAfee.

I would consult with Technical Support Chat regarding what to do when you have the firewall in any non-standard configurations.

However if you are reading from the Inbound Events there is no need to do anything unless you get a popup asking for permission.

Message was edited by: Ex_Brit on 18/10/10 7:34:28 EDT AM
How Many Badges Can You Collect?
Ready for a little competition? Members like you are earning badges and unlocking perks for their helpful answers. Are you? Click here to find out.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community