Solved

Network broadcasts and hundreds of ARP cache entries when viewing wityh arp-a

Posted on 2003-12-10
12
383 Views
Last Modified: 2010-04-14
I noticed quite a bit of network traffic on my switches. I identified the network card that was sending out the broadcasts, it was on a new Windows 2000 with RIS & DHCP installed. It is also a DC. When I do a arp -a I can see hundreds of entries such as 10.0.0.2  0000000000000, where the 0000000000000 should be a MAC address its all zero's which make sense as I only have one PC attached to this server. It is as if it is running through all the possible combinations of the DHCP server and trying to resolve a MAC address.

If I re boot it calms down but start after about ten minutes

Any ideas    
0
Comment
Question by:johncharnock
  • 6
  • 3
  • 2
  • +1
12 Comments
 
LVL 4

Expert Comment

by:Vinnnnie
Comment Utility
What happens if you disable DHCP? I would not be surprised that a faulty/inconfigured DHCP server would cause a lot of traffic on a network with one PC.
0
 
LVL 32

Accepted Solution

by:
Luc Franken earned 250 total points
Comment Utility
0
 
LVL 40

Expert Comment

by:Fatal_Exception
Comment Utility
Also, it is not recommended to put RIS on a DC.  Although it may not be your problem, I thought I might mention it.

Other than that, how is everyone doing today?

FE
0
 
LVL 32

Expert Comment

by:Luc Franken
Comment Utility
>>Other than that, how is everyone doing today?
I found two orange lights on the server,
A workstations harddisk failed,
Internet site of our company wasn't available today,
E-mail wasn't working today,
Talking about a really bad day :-( Thank god eveything is working now....
0
 
LVL 40

Expert Comment

by:Fatal_Exception
Comment Utility
I started to read you comment and thought you were writing a poem.  :)

Remember last Monday when you asked where I was all day?  Yep, sometimes Wednesday feels like Monday!

FE
0
 
LVL 32

Expert Comment

by:Luc Franken
Comment Utility
>and thought you were writing a poem
I wish I was writing one, today was one of the worst days I've ever had at work. :-(

>Yep, sometimes Wednesday feels like Monday!
Lol!
0
Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

 

Author Comment

by:johncharnock
Comment Utility
Its not a faulty card as this is a new intel server board with two NICs both have the same problem. It not a Virus as it is a new Install.

John
0
 
LVL 32

Expert Comment

by:Luc Franken
Comment Utility
>Its not a faulty card as this is a new intel server board with two NICs both have the same problem.
And what tells you the motherboard isn't faulty? Please try to disable both nics and install another one.

>It not a Virus as it is a new Install.
Sorry to say this, but I get really terrified by these kind of comments. Please try scanning for virusses, you can never do this too many times. If it won't help, at least it can't hurt either.
0
 
LVL 32

Expert Comment

by:Luc Franken
Comment Utility
Please try this:

taken from http://www.grc.com/dos/grcdos.htm
---------------------------------------------------------------------------------------------------------------------
A Quick & Easy Check for IRC Zombie/Bots

If you have managed to read all the way through this lengthy and detailed adventure, I am sure you will agree that you do NOT want any of these nasty Zombies or their relatives running around loose inside your PC. Fortunately, it's quite easy to verify that your system is not currently infected by one of these IRC Zombie/Bots.

All of the IRC Zombie/Bots open and maintain static connections to remote IRC chat servers whenever the host PC is connected to the Internet. Although it is possible for an IRC chat server to be configured to run on a port other than "6667", every instance I have seen has used the IRC default port of "6667".

Consequently, an active connection to an IRC server can be detected with the following command:

netstat -an | find ":6667"
Open an MS-DOS Prompt window and type the command line above, then press the "Enter" key. If a line resembling the one shown below is NOT displayed, your computer does not have an open connection to an IRC server running on the standard IRC port. If, however, you see something like this:
 

TCP   192.168.1.101:1026   70.13.215.89:6667  ESTABLISHED
 . . . then the only question remaining is how quickly you can disconnect your PC from the Internet!
A second and equally useful test can also be performed. Since IRC servers generally require the presence of an "Ident" server on the client machine, IRC clients almost always include a local "Ident server" to keep the remote IRC server happy. Every one of the Zombie/Bots I have examined does this. Therefore, the detection of an Ident server running in your machine would be another good cause for alarm. To quickly check for an Ident server, type the following command at an MS-DOS Prompt:

netstat -an | find ":113 "
As before, a blank line indicates that there is no Ident server running on the default Ident port of "113". (Note the "space" after the 113 and before the closing double-quote.) If, however, you see something like this:
 

TCP     0.0.0.0:113     0.0.0.0:0     LISTENING
 . . . then it's probably time to pull the plug on your cable-modem!  
---------------------------------------------------------------------------------------------------------------------


0
 

Author Comment

by:johncharnock
Comment Utility
LucF

You were right it was a virus, I had connected to the internet bofore applying SP 4 it was the nachi virus

Thanks
0
 
LVL 32

Expert Comment

by:Luc Franken
Comment Utility
Glad to see your problem is solved ;-)
0
 
LVL 40

Expert Comment

by:Fatal_Exception
Comment Utility
Cool.  Nasty things, those virii.  

Morning, or afternoon to you LucF
0

Featured Post

Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
A safe way to clean winsxs folder from your windows server 2008 R2 editions
This video discusses moving either the default database or any database to a new volume.
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

8 Experts available now in Live!

Get 1:1 Help Now