Solved

Analyzing traffic (ping requests I didnt do etc)

Posted on 2004-09-04
2
239 Views
Last Modified: 2010-04-11
Watched some traffic this morning .  I saw a few ping requests, that I didnt iniate, from the pc downstairs. No one was home but me.

192.168.1.8 (host) first did an ARP request to locate my router (192.168.1.40).
It then got the MAC and sent a ping request
192.168.1.40 replied


A few minutes later, another pc in my network sent a ping request to the same router (192.168.1.40)

What is up with this?

2. 192.168.2.2 is doing SNMP broadcasts. It's a wireless access point. Is this normal? I'm assuming it's broadcasting information so an SNMP server can pick it up? (even though I do not have an SNMP server)

3. Seeing my DHCP server doing some broadcasts.  (DHCP inform, DHCP acks).  What is this?
Thanks
0
Comment
Question by:dissolved
2 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 11980247
Sounds like a Microsoft PC performing dead gateway detection to make sure the default gateway is still alive. Normal behavior

2. Yes, unless you specifically configure the AP with the proper community strings and take out the default broadcast address for snmp traps, you will see this kind of traffic.

3. Exactly what you think they are. Informs and acks. The DHCP server maintains contact with client every once in a while and vice versa. The timing depends on the length of the lease. If 1/2 of the lease period is expired, then several conversations begin between the client and server. "can I renew my lease early?" "sure, why not" "do you have any changes for me?" "nope, use what I gave you last time"... etc..
0
 
LVL 4

Expert Comment

by:HackLife
ID: 11982061
lrmoore, well said.
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

Configuring network clients can be a chore, especially if there are a large number of them or a lot of itinerant users.  DHCP dynamically manages this process, much to the relief of users and administrators alike!
Don’t let your business fall victim to the coming apocalypse – use our Survival Guide for the Fax Apocalypse to identify the risks and signs of zombie fax activities at your business.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now