Solved

Analyzing traffic (ping requests I didnt do etc)

Posted on 2004-09-04
2
264 Views
Last Modified: 2010-04-11
Watched some traffic this morning .  I saw a few ping requests, that I didnt iniate, from the pc downstairs. No one was home but me.

192.168.1.8 (host) first did an ARP request to locate my router (192.168.1.40).
It then got the MAC and sent a ping request
192.168.1.40 replied


A few minutes later, another pc in my network sent a ping request to the same router (192.168.1.40)

What is up with this?

2. 192.168.2.2 is doing SNMP broadcasts. It's a wireless access point. Is this normal? I'm assuming it's broadcasting information so an SNMP server can pick it up? (even though I do not have an SNMP server)

3. Seeing my DHCP server doing some broadcasts.  (DHCP inform, DHCP acks).  What is this?
Thanks
0
Comment
Question by:dissolved
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 11980247
Sounds like a Microsoft PC performing dead gateway detection to make sure the default gateway is still alive. Normal behavior

2. Yes, unless you specifically configure the AP with the proper community strings and take out the default broadcast address for snmp traps, you will see this kind of traffic.

3. Exactly what you think they are. Informs and acks. The DHCP server maintains contact with client every once in a while and vice versa. The timing depends on the length of the lease. If 1/2 of the lease period is expired, then several conversations begin between the client and server. "can I renew my lease early?" "sure, why not" "do you have any changes for me?" "nope, use what I gave you last time"... etc..
0
 
LVL 4

Expert Comment

by:HackLife
ID: 11982061
lrmoore, well said.
0

Featured Post

Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article is a collection of issues that people face from time to time and possible solutions to those issues. I hope you enjoy reading it.
WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question