<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What's all this TR064 stuff in My Router</title>
    <link>https://community.plus.net/t5/My-Router/What-s-all-this-TR064-stuff/m-p/1435840#M3165</link>
    <description>&lt;P&gt;Having just rebooted the Win7 PC and then looking in the Resource Monitor/Network, it's &lt;EM&gt;&lt;STRONG&gt;svchost.exe(netsvcs)&lt;/STRONG&gt;&lt;/EM&gt; that's doing it. Not sure what that actually does?&lt;/P&gt;</description>
    <pubDate>Mon, 01 May 2017 12:47:37 GMT</pubDate>
    <dc:creator>MartyPop</dc:creator>
    <dc:date>2017-05-01T12:47:37Z</dc:date>
    <item>
      <title>What's all this TR064 stuff</title>
      <link>https://community.plus.net/t5/My-Router/What-s-all-this-TR064-stuff/m-p/1435649#M3153</link>
      <description>&lt;P&gt;A couple of days ago, I started seeing stuff in my PlusNet Hub One firewall logfile which I've never seen before. As you can see from the following logfile extract, it repeats itself approximately every 30 seconds:&lt;/P&gt;
&lt;PRE&gt;08:51:02, 30 Apr.	(1385562.210000) Port forwarding rule added via UPnP/TR064. Protocol: UDP, external ports: any-​&amp;gt;64208, internal ports: 64208, internal client: 192.168.1.65
08:50:27, 30 Apr.	(1385527.580000) Port forwarding rule added via UPnP/TR064. Protocol: UDP, external ports: any-​&amp;gt;64208, internal ports: 64208, internal client: 192.168.1.65
08:49:47, 30 Apr.	(1385487.580000) Port forwarding rule added via UPnP/TR064. Protocol: UDP, external ports: any-​&amp;gt;64208, internal ports: 64208, internal client: 192.168.1.65
08:49:14, 30 Apr.	(1385454.800000) Port forwarding rule added via UPnP/TR064. Protocol: UDP, external ports: any-​&amp;gt;64208, internal ports: 64208, internal client: 192.168.1.65
08:48:33, 30 Apr.	(1385413.620000) Port forwarding rule added via UPnP/TR064. Protocol: UDP, external ports: any-​&amp;gt;64208, internal ports: 64208, internal client: 192.168.1.65
08:47:53, 30 Apr.	(1385373.350000) Port forwarding rule added via UPnP/TR064. Protocol: UDP, external ports: any-​&amp;gt;64208, internal ports: 64208, internal client: 192.168.1.65
08:47:16, 30 Apr.	(1385336.430000) Port forwarding rule added via UPnP/TR064. Protocol: UDP, external ports: any-​&amp;gt;64208, internal ports: 64208, internal client: 192.168.1.65
08:46:38, 30 Apr.	(1385297.970000) Port forwarding rule added via UPnP/TR064. Protocol: UDP, external ports: any-​&amp;gt;64208, internal ports: 64208, internal client: 192.168.1.65
08:46:03, 30 Apr.	(1385263.190000) Port forwarding rule added via UPnP/TR064. Protocol: UDP, external ports: any-​&amp;gt;64208, internal ports: 64208, internal client: 192.168.1.65&lt;/PRE&gt;
&lt;P&gt;Anyone know what's going on here ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Apr 2017 08:09:08 GMT</pubDate>
      <guid>https://community.plus.net/t5/My-Router/What-s-all-this-TR064-stuff/m-p/1435649#M3153</guid>
      <dc:creator>MartyPop</dc:creator>
      <dc:date>2017-04-30T08:09:08Z</dc:date>
    </item>
    <item>
      <title>Re: What's all this TR064 stuff</title>
      <link>https://community.plus.net/t5/My-Router/What-s-all-this-TR064-stuff/m-p/1435656#M3154</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/27111"&gt;@MartyPop&lt;/a&gt;, are you or anyone else in the house running games consoles or similar? This TR064 protocol is LAN sided so these entries are coming from inside your network specifically 192.168.1.65), so to start with what device has this address?&lt;/P&gt;</description>
      <pubDate>Sun, 30 Apr 2017 08:56:19 GMT</pubDate>
      <guid>https://community.plus.net/t5/My-Router/What-s-all-this-TR064-stuff/m-p/1435656#M3154</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2017-04-30T08:56:19Z</dc:date>
    </item>
    <item>
      <title>Re: What's all this TR064 stuff</title>
      <link>https://community.plus.net/t5/My-Router/What-s-all-this-TR064-stuff/m-p/1435693#M3157</link>
      <description>&lt;P&gt;Nope, no games consoles or similar here.&lt;/P&gt;
&lt;P&gt;The device with that IP is my Win7 PC.&lt;/P&gt;
&lt;P&gt;However, a strange thing happened within 10 minutes of posting my original post --&amp;gt; the TR064 stuff stopped!?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Apr 2017 11:47:20 GMT</pubDate>
      <guid>https://community.plus.net/t5/My-Router/What-s-all-this-TR064-stuff/m-p/1435693#M3157</guid>
      <dc:creator>MartyPop</dc:creator>
      <dc:date>2017-04-30T11:47:20Z</dc:date>
    </item>
    <item>
      <title>Re: What's all this TR064 stuff</title>
      <link>https://community.plus.net/t5/My-Router/What-s-all-this-TR064-stuff/m-p/1435701#M3158</link>
      <description>&lt;P&gt;That's weird, best to keep an eye on the logs to see if returns, it might give you an idea as to what or why it is being done.&lt;/P&gt;</description>
      <pubDate>Sun, 30 Apr 2017 11:58:53 GMT</pubDate>
      <guid>https://community.plus.net/t5/My-Router/What-s-all-this-TR064-stuff/m-p/1435701#M3158</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2017-04-30T11:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: What's all this TR064 stuff</title>
      <link>https://community.plus.net/t5/My-Router/What-s-all-this-TR064-stuff/m-p/1435798#M3162</link>
      <description>&lt;P&gt;The last thing I did before switching off my Win7 PC yesterday was to check my Hub One firewall logfile and it definitely hadn't started again. The first thing I did after booting my Win7 PC this morning was to have a look at the Hub One firewall logfile and there it was again. All this went on for just over an hour and then stopped but the last entry in the logfile was slightly different to all the others:&lt;/P&gt;
&lt;PRE&gt;09:26:09, 01 May.	(1474067.640000) Port forwarding rule &lt;STRONG&gt;deleted&lt;/STRONG&gt; via UPnP/TR064. Protocol: UDP, external ports: any-​&amp;gt;64208, internal ports: 64208, internal client: 192.168.1.65&lt;/PRE&gt;
&lt;P&gt;Whatever it is that's trying to create a port forwarding rule is then trying to delete the rule but as this is all in the firewall logfile, it shows that the firewall is doing its job. All I need to do now is to figure out what's attempting to create the port forwarding rule but how I do that eludes me at the moment. For starters, I ran a full AV scan yesterday afternoon which found nothing.&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2017 08:57:07 GMT</pubDate>
      <guid>https://community.plus.net/t5/My-Router/What-s-all-this-TR064-stuff/m-p/1435798#M3162</guid>
      <dc:creator>MartyPop</dc:creator>
      <dc:date>2017-05-01T08:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: What's all this TR064 stuff</title>
      <link>https://community.plus.net/t5/My-Router/What-s-all-this-TR064-stuff/m-p/1435815#M3163</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/27111"&gt;@MartyPop&lt;/a&gt; - One option is to run netstat on the Windows machine. Start my running the Task Manager, then open a DOS command prompt and execute :&lt;/P&gt;
&lt;PRE&gt;netstat -ano | more&lt;/PRE&gt;
&lt;P&gt;This should give you the PID of the application making the request, but you may need to run it several time to capture what you need.&lt;/P&gt;
&lt;P&gt;Or you can use &lt;A title="CurrPorts" href="http://www.nirsoft.net/utils/cports.html" target="_blank"&gt;currports&lt;/A&gt; from NirSoft this may be easier to use as it has a GUI and due to the timed nature of the requests. Once you know the PID or you have the name of the application making these requests you'll be able to decide as to what the next step should be.&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2017 09:58:53 GMT</pubDate>
      <guid>https://community.plus.net/t5/My-Router/What-s-all-this-TR064-stuff/m-p/1435815#M3163</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2017-05-01T09:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: What's all this TR064 stuff</title>
      <link>https://community.plus.net/t5/My-Router/What-s-all-this-TR064-stuff/m-p/1435818#M3164</link>
      <description>&lt;P&gt;I find the Resource Monitor/Network usefull as well as netstat for looking at dubious stuff in windows.&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2017 10:08:35 GMT</pubDate>
      <guid>https://community.plus.net/t5/My-Router/What-s-all-this-TR064-stuff/m-p/1435818#M3164</guid>
      <dc:creator>30FTTC06</dc:creator>
      <dc:date>2017-05-01T10:08:35Z</dc:date>
    </item>
    <item>
      <title>Re: What's all this TR064 stuff</title>
      <link>https://community.plus.net/t5/My-Router/What-s-all-this-TR064-stuff/m-p/1435840#M3165</link>
      <description>&lt;P&gt;Having just rebooted the Win7 PC and then looking in the Resource Monitor/Network, it's &lt;EM&gt;&lt;STRONG&gt;svchost.exe(netsvcs)&lt;/STRONG&gt;&lt;/EM&gt; that's doing it. Not sure what that actually does?&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2017 12:47:37 GMT</pubDate>
      <guid>https://community.plus.net/t5/My-Router/What-s-all-this-TR064-stuff/m-p/1435840#M3165</guid>
      <dc:creator>MartyPop</dc:creator>
      <dc:date>2017-05-01T12:47:37Z</dc:date>
    </item>
    <item>
      <title>Re: What's all this TR064 stuff</title>
      <link>https://community.plus.net/t5/My-Router/What-s-all-this-TR064-stuff/m-p/1435843#M3166</link>
      <description>&lt;P&gt;Well at least you know it's not malicious which is always a good thing.&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2017 13:01:25 GMT</pubDate>
      <guid>https://community.plus.net/t5/My-Router/What-s-all-this-TR064-stuff/m-p/1435843#M3166</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2017-05-01T13:01:25Z</dc:date>
    </item>
    <item>
      <title>Re: What's all this TR064 stuff</title>
      <link>https://community.plus.net/t5/My-Router/What-s-all-this-TR064-stuff/m-p/1435844#M3167</link>
      <description>&lt;P&gt;Very possibly it's Teredo ,&amp;nbsp;&lt;A href="https://answers.microsoft.com/en-us/windows/forum/windows_8-networking/teredo-and-upnp/5657f953-b493-4799-8a63-498c308983eb" target="_blank"&gt;https://answers.microsoft.com/en-us/windows/forum/windows_8-networking/teredo-and-upnp/5657f953-b493-4799-8a63-498c308983eb&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Although why it would stop after an hour I'm not sure ...&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2017 13:02:21 GMT</pubDate>
      <guid>https://community.plus.net/t5/My-Router/What-s-all-this-TR064-stuff/m-p/1435844#M3167</guid>
      <dc:creator>MisterW</dc:creator>
      <dc:date>2017-05-01T13:02:21Z</dc:date>
    </item>
  </channel>
</rss>

