N
Nathan Thomas Sr
I have this strange problem I've been trying to track down. I'm not
entirely sure this is where this should go, but I'm not aware of any
other forum to post this in.
I implemented a new firewall unit the other week. Lately, I've been
paying more attention to the logs. In the Intrusion Detection System
log, I keep seeing this message:
Date: 08/15 08:50:45 Name: ICMP Destination Unreachable (Communication
Administratively Prohibited)
Priority: 3 Type: Misc activity
IP info: 192.168.0.5:123 -> 169.254.122.72:123
References: none found
In the Firewall log:
08:52:31 eth0 eth1 ICMP
192.168.0.5:137----> 169.254.122.72:137
-------
For some reason or the other, the 192. address is sending netbios
requests to the 169 address. I can't figure out why. I made sure that
there were no errant/bad records in DNS, disabled netbios on that NIC,
even deleted the 2nd nic from the server since it's not running
Multihomed anymore. Still, there firewall log shows that even every 2-3
seconds, and the intrusion log shows the 1st error every so often.
There were no records of this over the weekend, and they started back up
this morning around 0815, which is when most employees get on the network.
Suggestions/advice?
thanks
entirely sure this is where this should go, but I'm not aware of any
other forum to post this in.
I implemented a new firewall unit the other week. Lately, I've been
paying more attention to the logs. In the Intrusion Detection System
log, I keep seeing this message:
Date: 08/15 08:50:45 Name: ICMP Destination Unreachable (Communication
Administratively Prohibited)
Priority: 3 Type: Misc activity
IP info: 192.168.0.5:123 -> 169.254.122.72:123
References: none found
In the Firewall log:
08:52:31 eth0 eth1 ICMP
192.168.0.5:137----> 169.254.122.72:137
-------
For some reason or the other, the 192. address is sending netbios
requests to the 169 address. I can't figure out why. I made sure that
there were no errant/bad records in DNS, disabled netbios on that NIC,
even deleted the 2nd nic from the server since it's not running
Multihomed anymore. Still, there firewall log shows that even every 2-3
seconds, and the intrusion log shows the 1st error every so often.
There were no records of this over the weekend, and they started back up
this morning around 0815, which is when most employees get on the network.
Suggestions/advice?
thanks