<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Outbound Traffic on UDP 3050 in Aerohive Migrated Content</title>
    <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/outbound-traffic-on-udp-3050/m-p/89435#M12323</link>
    <description>&lt;P&gt;HI, I am a SOC Analyst who is working with one of my clients. I was doing a port inspection, and noticed a high number of outbound requests on UDP 3050. They all seem to be about 500 bytes. No traffic is witnessed inbound.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The client believes this traffic is coming from their wireless access point. The client states that they are running:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;on premises Hive Manager Software Version: 8.2r2c&lt;/LI&gt;	&lt;LI&gt;AP model AP250 running HiveOS 8.0r1.162054&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The client has reported that these are older Manager and Firmware models, and plans to upgrade.&lt;/P&gt;&lt;P&gt;Any help in identifying this traffic and stopping it would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;P.S. I’m guessing the Sub-Forum. Please let me know if I need to move this post to the proper forum&lt;/P&gt;</description>
    <pubDate>Fri, 14 Aug 2020 18:17:19 GMT</pubDate>
    <dc:creator>Paul_M</dc:creator>
    <dc:date>2020-08-14T18:17:19Z</dc:date>
    <item>
      <title>Outbound Traffic on UDP 3050</title>
      <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/outbound-traffic-on-udp-3050/m-p/89435#M12323</link>
      <description>&lt;P&gt;HI, I am a SOC Analyst who is working with one of my clients. I was doing a port inspection, and noticed a high number of outbound requests on UDP 3050. They all seem to be about 500 bytes. No traffic is witnessed inbound.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The client believes this traffic is coming from their wireless access point. The client states that they are running:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;on premises Hive Manager Software Version: 8.2r2c&lt;/LI&gt;	&lt;LI&gt;AP model AP250 running HiveOS 8.0r1.162054&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The client has reported that these are older Manager and Firmware models, and plans to upgrade.&lt;/P&gt;&lt;P&gt;Any help in identifying this traffic and stopping it would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;P.S. I’m guessing the Sub-Forum. Please let me know if I need to move this post to the proper forum&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2020 18:17:19 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/aerohive-migrated-content/outbound-traffic-on-udp-3050/m-p/89435#M12323</guid>
      <dc:creator>Paul_M</dc:creator>
      <dc:date>2020-08-14T18:17:19Z</dc:date>
    </item>
    <item>
      <title>Re: Outbound Traffic on UDP 3050</title>
      <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/outbound-traffic-on-udp-3050/m-p/89436#M12324</link>
      <description>&lt;P&gt;Hello Paul, my first thought is IP tracking, do you know if that is enabled in your policy? This page reviews IP tracking for reference:&amp;nbsp;&lt;A href="http://docs.aerohive.com/330000/docs/help/english/ng/Content/gui/configuration/configuring-ip-tracking-groups.htm?Highlight=IP%20tracking" target="_blank" rel="nofollow noreferrer noopener"&gt;http://docs.aerohive.com/330000/docs/help/english/ng/Content/gui/configuration/configuring-ip-tracking-groups.htm?Highlight=IP%20tracking&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Aug 2020 02:21:32 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/aerohive-migrated-content/outbound-traffic-on-udp-3050/m-p/89436#M12324</guid>
      <dc:creator>SamPirok</dc:creator>
      <dc:date>2020-08-15T02:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: Outbound Traffic on UDP 3050</title>
      <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/outbound-traffic-on-udp-3050/m-p/89437#M12325</link>
      <description>&lt;P&gt;Sam, after reading this, I think you may be on to something. One thing I noticed was that there seemed to be a pattern in the IP addresses using the port. Certain ip ranges (like a .19) seemed to be present more in the findings. I’ll run this by my client with their weekly report. I’ll keep you in the loop. Thanks for the pointer.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Aug 2020 18:05:14 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/aerohive-migrated-content/outbound-traffic-on-udp-3050/m-p/89437#M12325</guid>
      <dc:creator>Paul_M</dc:creator>
      <dc:date>2020-08-16T18:05:14Z</dc:date>
    </item>
  </channel>
</rss>

