Solved

Analyzing traffic (ping requests I didnt do etc)

Posted on 2004-09-04
2
257 Views
Last Modified: 2010-04-11
Watched some traffic this morning .  I saw a few ping requests, that I didnt iniate, from the pc downstairs. No one was home but me.

192.168.1.8 (host) first did an ARP request to locate my router (192.168.1.40).
It then got the MAC and sent a ping request
192.168.1.40 replied


A few minutes later, another pc in my network sent a ping request to the same router (192.168.1.40)

What is up with this?

2. 192.168.2.2 is doing SNMP broadcasts. It's a wireless access point. Is this normal? I'm assuming it's broadcasting information so an SNMP server can pick it up? (even though I do not have an SNMP server)

3. Seeing my DHCP server doing some broadcasts.  (DHCP inform, DHCP acks).  What is this?
Thanks
0
Comment
Question by:dissolved
2 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 11980247
Sounds like a Microsoft PC performing dead gateway detection to make sure the default gateway is still alive. Normal behavior

2. Yes, unless you specifically configure the AP with the proper community strings and take out the default broadcast address for snmp traps, you will see this kind of traffic.

3. Exactly what you think they are. Informs and acks. The DHCP server maintains contact with client every once in a while and vice versa. The timing depends on the length of the lease. If 1/2 of the lease period is expired, then several conversations begin between the client and server. "can I renew my lease early?" "sure, why not" "do you have any changes for me?" "nope, use what I gave you last time"... etc..
0
 
LVL 4

Expert Comment

by:HackLife
ID: 11982061
lrmoore, well said.
0

Featured Post

Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
replacing 2811 to ISR 4331 2 39
Networking Monitoring Tools 10 65
Sonos and 5ghz 14 42
Network adapter failed to start 5 33
#Citrix #Citrix Netscaler #HTTP Compression #Load Balance
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

685 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question