Solved

Analyzing traffic (ping requests I didnt do etc)

Posted on 2004-09-04
2
245 Views
Last Modified: 2010-04-11
Watched some traffic this morning .  I saw a few ping requests, that I didnt iniate, from the pc downstairs. No one was home but me.

192.168.1.8 (host) first did an ARP request to locate my router (192.168.1.40).
It then got the MAC and sent a ping request
192.168.1.40 replied


A few minutes later, another pc in my network sent a ping request to the same router (192.168.1.40)

What is up with this?

2. 192.168.2.2 is doing SNMP broadcasts. It's a wireless access point. Is this normal? I'm assuming it's broadcasting information so an SNMP server can pick it up? (even though I do not have an SNMP server)

3. Seeing my DHCP server doing some broadcasts.  (DHCP inform, DHCP acks).  What is this?
Thanks
0
Comment
Question by:dissolved
2 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 11980247
Sounds like a Microsoft PC performing dead gateway detection to make sure the default gateway is still alive. Normal behavior

2. Yes, unless you specifically configure the AP with the proper community strings and take out the default broadcast address for snmp traps, you will see this kind of traffic.

3. Exactly what you think they are. Informs and acks. The DHCP server maintains contact with client every once in a while and vice versa. The timing depends on the length of the lease. If 1/2 of the lease period is expired, then several conversations begin between the client and server. "can I renew my lease early?" "sure, why not" "do you have any changes for me?" "nope, use what I gave you last time"... etc..
0
 
LVL 4

Expert Comment

by:HackLife
ID: 11982061
lrmoore, well said.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now