Today I have been getting hammered with the ZA firewall getting triggered over and over with an "allow/deny" warning for SVCHOST.EXE that "WIN32 services wants to accept connections from the internet." I have repeatedly clicked "deny" (didn't want to click "always deny" in case I lose some functionality that is hard to track down in ZA and restore). The ZA log file information is pasted below.

Can anyone tell me is happening here, and what tserv3.fmt2.ipv6.he.net might be?

The root of the address is Hurricane Electric, which is apparently involved with Internet Protocoal V.6. But I don't know what might be on their servers,*who owns that full address, or what is going on here.

----- Log Entry -----

Description Packet sent from 72.52.104.74 (UDP Port 3545) to 192.168.1.146 (UDP Port 1036) was blocked

Rating Medium

Date / Time 2009-09-05 16:57:10-8:00

Type Firewall

Protocol UDP

Program

Source IP 72.52.104.74:3545

Destination IP 192.168.1.146:1036

Direction Incoming

Action Taken Blocked

Count 1

Source DNS tserv3.fmt2.ipv6.he.net

Destination DNS D-D630

Policy Personal Policy

Rule ExtBlockAll2


.wysiwyg { background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; background-color: #f5f5ff; background-image: none; color: #000000; font-family: Verdana, Arial, Arial; font-style: normal; font-variant: normal; font-weight: 400; font-size: 10pt; line-height: normal; margin-top: 5px; margin-right: 10px; margin-bottom: 10px; margin-left: 10px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px } .wysiwyg a:link, .wysiwyg_alink { color: #22229c } .wysiwyg a:visited, .wysiwyg_avisited { color: #22229c } .wysiwyg a:hover, .wysiwyg a:active, .wysiwyg_ahover { color: #99cc33 } p { margin: 0px; } .inlineimg { vertical-align: middle; }