Networking Forums

Networking Forums > Computer Networking > Windows Networking > Attempted connection to APIPA Address

Reply
Thread Tools Display Modes

Attempted connection to APIPA Address

 
 
Shawn McCabe
Guest
Posts: n/a

 
      11-30-2007, 05:44 PM
Seeing some strange activity from 3 of our exchange servers and one DC (A
global catalog server) all Windows Server 2003.

Firewall logs are showing multiple blocked attempted connections to the
internet by servers to mainly APIPA addresses - over multiple different
ports. i.e.

Source: DC
Service: TCP 1270 (ports always varies)
Destination: 169.254.241.60 (address always varies but is usually APIPA).

When running port reporter, netstat, or TCPView on offending servers -
traffic can not be seen...

Initially considered spoofing but firewall was able to determine correct MAC
address of NIC.

Anyone ever seen this or anything like it?



 
Reply With Quote
 
 
 
 
Meinolf Weber
Guest
Posts: n/a

 
      11-30-2007, 08:41 PM
Hello Shawn,

The easiest and recommended way for servers with multiple NIC's which are
not teamed or in use is to disable then. Also i assume the apipa will sometimes
try to reach a DHCP server, which can declare the traffic also to the internet.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.dts-l.org/goodpost.htm

> Seeing some strange activity from 3 of our exchange servers and one DC
> (A global catalog server) all Windows Server 2003.
>
> Firewall logs are showing multiple blocked attempted connections to
> the internet by servers to mainly APIPA addresses - over multiple
> different ports. i.e.
>
> Source: DC
> Service: TCP 1270 (ports always varies)
> Destination: 169.254.241.60 (address always varies but is usually
> APIPA).
> When running port reporter, netstat, or TCPView on offending servers -
> traffic can not be seen...
>
> Initially considered spoofing but firewall was able to determine
> correct MAC address of NIC.
>
> Anyone ever seen this or anything like it?
>



 
Reply With Quote
 
Meinolf Weber
Guest
Posts: n/a

 
      12-02-2007, 06:58 PM
Hello Meinolf Weber,

Reread my posting and have to change from DHCP server to DNS server which
i mean.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.dts-l.org/goodpost.htm

> Hello Shawn,
>
> The easiest and recommended way for servers with multiple NIC's which
> are not teamed or in use is to disable then. Also i assume the apipa
> will sometimes try to reach a DHCP server, which can declare the
> traffic also to the internet.
>
> Best regards
>
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and
> confers
> no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!! http://www.dts-l.org/goodpost.htm
>> Seeing some strange activity from 3 of our exchange servers and one
>> DC (A global catalog server) all Windows Server 2003.
>>
>> Firewall logs are showing multiple blocked attempted connections to
>> the internet by servers to mainly APIPA addresses - over multiple
>> different ports. i.e.
>>
>> Source: DC
>> Service: TCP 1270 (ports always varies)
>> Destination: 169.254.241.60 (address always varies but is usually
>> APIPA).
>> When running port reporter, netstat, or TCPView on offending servers
>> -
>> traffic can not be seen...
>> Initially considered spoofing but firewall was able to determine
>> correct MAC address of NIC.
>>
>> Anyone ever seen this or anything like it?
>>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
RRAS Internal interface using APIPA address, ignoring both DHCP an Jacques Assert Windows Networking 5 05-05-2008 02:59 AM
how to get a fast zero-config (APIPA) IP address assignment at link start? robin Wireless Networks 4 02-17-2006 11:41 PM
Monitoring Attempted Access? DW Wireless Internet 2 01-06-2006 05:53 AM
Just how worried should I be about an attempted connection to my wireless network? MBK Wireless Internet 5 01-22-2004 03:44 AM
APIPA Ragunathan M Windows Networking 2 11-28-2003 05:07 AM



1 2 3 4 5 6 7 8 9 10 11