MX68 allowing UDP 500 from internet

bszweda
New here

MX68 allowing UDP 500 from internet

Hi All,

 

I was checking my firewall logs on a MX68 and found one accepted connection over 500 UDP from an unauthorized IP address. This device does have an IPSEC site to site tunnel configured. ( Meraki to AWS) I just want to confirm this normal behavior due to using IPSEC site to site tunnels.  I do see "All networks"  is selected for availability.  Has anyone else encountered this before? 

 

Thanks

 

1 Reply 1
Obrez
Here to help

UDP 500 is used for ISAKMP phase 1 for tunnel encryption.  It is normal.

 

Cheers!

Get notified when there are additional replies to this discussion.