Networking Forums

Networking Forums > Computer Networking > Windows Networking > netbios-dgm hits

Reply
Thread Tools Display Modes

netbios-dgm hits

 
 
Knowledge
Guest
Posts: n/a

 
      02-27-2007, 02:51 PM
Every few minutes my firewall gets hit with netbios-dgm hits. Not sure what
is causing this. It is trying to connect servers which are not even on the
network. Scanvenged dns and wns, restarted machice, cleared cache from the
machine but nothing works.

Here is the output log from pix filewall.. (pasted only three lines but
there are hundrends like this getting generated)
xx.41 seems to be generating this but not sure what program does it. any
help would be appreciated.

Unknown 10.xx.xx.6 Unknown 3 26th Feb 2007, 00:00:00 %PIX-4-106023: Deny tcp
src inside:10.xx.xx.41/139 dst outside:10.1.1.6/14636 by access-group
"acl-outbound"
Unknown 10.xx.xx.20 netbios-dgm 3 26th Feb 2007, 00:00:00 %PIX-2-106006:
Deny inbound UDP from 10.xx.xx.41/138 to 10.xx.xx.xx/138 on interface inside
Unknown 10.xx.xx.xx netbios-dgm 3 26th Feb 2007, 00:00:00 %PIX-2-106006:
Deny inbound UDP from 10.xx.xx.41/138 to 10.xx.xx.xx/138 on interface inside


 
Reply With Quote
 
 
 
 
Michael Giorgio - MS MVP
Guest
Posts: n/a

 
      03-01-2007, 01:03 PM
Looks to be a NetBIOS storm from inside. I would start
with the 10.xx.xx.41 machine. UDP 137, 138 and TCP
139 are primarily used for authentication.

"Knowledge" <(E-Mail Removed)> wrote in message news:..
> Every few minutes my firewall gets hit with netbios-dgm hits. Not sure
> what
> is causing this. It is trying to connect servers which are not even on
> the
> network. Scanvenged dns and wns, restarted machice, cleared cache from
> the
> machine but nothing works.
>
> Here is the output log from pix filewall.. (pasted only three lines but
> there are hundrends like this getting generated)
> xx.41 seems to be generating this but not sure what program does it. any
> help would be appreciated.
>
> Unknown 10.xx.xx.6 Unknown 3 26th Feb 2007, 00:00:00 %PIX-4-106023: Deny
> tcp
> src inside:10.xx.xx.41/139 dst outside:10.1.1.6/14636 by access-group
> "acl-outbound"
> Unknown 10.xx.xx.20 netbios-dgm 3 26th Feb 2007, 00:00:00 %PIX-2-106006:
> Deny inbound UDP from 10.xx.xx.41/138 to 10.xx.xx.xx/138 on interface
> inside
> Unknown 10.xx.xx.xx netbios-dgm 3 26th Feb 2007, 00:00:00 %PIX-2-106006:
> Deny inbound UDP from 10.xx.xx.41/138 to 10.xx.xx.xx/138 on interface
> inside
>
>



 
Reply With Quote
 
Knowledge
Guest
Posts: n/a

 
      03-06-2007, 03:01 PM
yes .41 is a Domain controller but what do I do to start looking for
information? I have looked into obivious programs none of which is
generating it.

Thanks

"Michael Giorgio - MS MVP" wrote:

> Looks to be a NetBIOS storm from inside. I would start
> with the 10.xx.xx.41 machine. UDP 137, 138 and TCP
> 139 are primarily used for authentication.
>
> "Knowledge" <(E-Mail Removed)> wrote in message news:..
> > Every few minutes my firewall gets hit with netbios-dgm hits. Not sure
> > what
> > is causing this. It is trying to connect servers which are not even on
> > the
> > network. Scanvenged dns and wns, restarted machice, cleared cache from
> > the
> > machine but nothing works.
> >
> > Here is the output log from pix filewall.. (pasted only three lines but
> > there are hundrends like this getting generated)
> > xx.41 seems to be generating this but not sure what program does it. any
> > help would be appreciated.
> >
> > Unknown 10.xx.xx.6 Unknown 3 26th Feb 2007, 00:00:00 %PIX-4-106023: Deny
> > tcp
> > src inside:10.xx.xx.41/139 dst outside:10.1.1.6/14636 by access-group
> > "acl-outbound"
> > Unknown 10.xx.xx.20 netbios-dgm 3 26th Feb 2007, 00:00:00 %PIX-2-106006:
> > Deny inbound UDP from 10.xx.xx.41/138 to 10.xx.xx.xx/138 on interface
> > inside
> > Unknown 10.xx.xx.xx netbios-dgm 3 26th Feb 2007, 00:00:00 %PIX-2-106006:
> > Deny inbound UDP from 10.xx.xx.41/138 to 10.xx.xx.xx/138 on interface
> > inside
> >
> >

>
>
>

 
Reply With Quote
 
Michael Giorgio - MS MVP
Guest
Posts: n/a

 
      03-09-2007, 07:09 PM
You could use Netmon or another sniffer to capture the data
from that particular server by filtering everything except that
tcp/ip address. Post the details if you want someone to
identify the packets. .

"Knowledge" <(E-Mail Removed)> wrote in message news:
> yes .41 is a Domain controller but what do I do to start looking for
> information? I have looked into obivious programs none of which is
> generating it.
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: iPhone share of U.S. traffic hits 69% Tim Murray Wireless Internet 36 06-30-2009 08:43 AM
SNMP hits to the router =?Utf-8?B?U2FudGhhbmE=?= Windows Networking 0 01-12-2005 04:49 AM
BT hits 90% ADSL coverage.. Sunil Sood Broadband 5 05-19-2004 06:48 PM
Earthquake Hits Essex!! Marky Broadband 3 05-13-2004 11:22 AM
BT ADSL coverage hits 80% Sunil Sood Broadband 6 09-11-2003 04:50 PM



1 2 3 4 5 6 7 8 9 10 11