Networking Forums

Networking Forums > Computer Networking > Windows Networking > Networking Problem "Packet Flood"

Reply
Thread Tools Display Modes

Networking Problem "Packet Flood"

 
 
=?Utf-8?B?QXVndXN0IFN0YXJ0eg==?=
Guest
Posts: n/a

 
      07-31-2004, 05:45 PM
On one of our Windows 2000 servers we are having a big problem with it sending out Thousands of TCP packets every second and flooding the network.

This server, also our exchange server, has been running fine for about 18 months, then all of a sudden this started. Once we reboot it it will run for anywhere between 45 minutes and 8 hours before it starts again.

I have ran virus scan, nothing was found, I installed the network cards, but that did not help. I have looked at netstat when this is happening but nothing looks out of order. I have use TCP view and it shows a lot of SYN_SENT. But I cant track down the problem.
Does any one have any ideas?
Thanks,

August

 
Reply With Quote
 
 
 
 
netneg
Guest
Posts: n/a

 
      08-02-2004, 01:29 PM
Check your TCP sessions and adjust properly. It could be a DoS. Machines can
send thousands of TCP connection requests and your server will respond with
an OK to create a connection, but then the other side never responds. The
server will wait X amount of time before timing out and releasing the
session. Servers will allow only Y amount of sessions, which is configurable
in the registry. Too many open sessions waiting, stops new (legit) sessions
from being established. Google for 'TCP_SYN attack' for more info. You might
want to sniff the network and see where all the SYN's are going and possibly
block that subnet/IP in your firewall.

"August Startz" <(E-Mail Removed)> wrote in message
newsA1C02FE-E52D-4C53-B28F-(E-Mail Removed)...
> On one of our Windows 2000 servers we are having a big problem with it

sending out Thousands of TCP packets every second and flooding the network.
>
> This server, also our exchange server, has been running fine for about 18

months, then all of a sudden this started. Once we reboot it it will run
for anywhere between 45 minutes and 8 hours before it starts again.
>
> I have ran virus scan, nothing was found, I installed the network cards,

but that did not help. I have looked at netstat when this is happening but
nothing looks out of order. I have use TCP view and it shows a lot of
SYN_SENT. But I cant track down the problem.
> Does any one have any ideas?
> Thanks,
>
> August
>



 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
[Fwd: SPEWS DOLTS "SneakyP", "Kevin!:?)", "WindsorFox" SPAM braodbandnewsgroup] !:?) Broadband 0 11-30-2005 01:04 AM
Re: SPEWS SLIMES "WindsorFox", "Kevin-!:?)", "Spin Dryer" get the cold shoulder at broadband ng! SneakyP Broadband 0 11-29-2005 10:46 PM
Attention Plus.net Re: SPEWS DOLTS "WindsorFox", "Kevin-!:?)", "SpinDryer" SPAM broadband newsgroup !:?) Broadband 0 11-28-2005 04:28 AM
Attention Plus.Net Re: SPEWS DOLTS "WindsorFox", "Kevin-!:?)", "SpinDryer" SPAM braodband newsgroup !:?) Broadband 0 11-28-2005 03:03 AM
networking problem "secur32.dll" missing Pat Liu Windows Networking 0 08-04-2003 11:55 PM



1 2 3 4 5 6 7 8 9 10 11