Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

How do I trace ICMP packets to the Windows process that is sending them?

Posted on 2007-04-11
3
Medium Priority
?
1,552 Views
Last Modified: 2013-11-29
Hi there,
 
I've got a system sending large ICMP packets that our firewall is detecting. This is not a major issue but they are oversized and are fragmenting. Which seems odd. They appear to be transmitted at somewhat regular intervals.
 
I would like to dertermine what process is generating these packets. I've seached and found suggestions but no program or tool that is comparable to TCPView.  Which is really what I'd like to see. I am a network administrator and compiling code on Windows is something I would like to avoid if possible. Ideally a pre-exisiting program to resolve this would be great.
 
Does anyone have a solution or suggestion on how to trace what process is sending these large ICMP packets?

I actually have 2 systems doing this: Windows 2000 Server, SP4 and Windows Server 2003 Standard.

-Wireshark does not tie packets to a process.
-TCPView does not sho ICMP traffic.
-I wonder if this is even possible.
 
Thanks,
 
Eric
0
Comment
Question by:erisler
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 2

Expert Comment

by:Micah_B
ID: 18890591
Hello,
Does the command "netstat" cover this function?
You could try a "netstat -p icmp" for starters.
Hope this helps
0
 

Author Comment

by:erisler
ID: 18917687
Netstat does not help. I've posted several forum messages and had no luck. I'm really looking for a program that will monitor for ICMP packets and show the following:

-ICMP statistics (packet size, etc).
-originating process

Thanks for the help.

Eric
0
 
LVL 5

Accepted Solution

by:
skaap2k earned 750 total points
ID: 18925127
A firewall like zonealarm will do something like this for you "Process X is trying to send a ping to x.x.x.x" .. do you want to allow this ... you could customise the app to just watch for ICMP traffic ..
0

Featured Post

Learn Veeam advantages over legacy backup

Every day, more and more legacy backup customers switch to Veeam. Technologies designed for the client-server era cannot restore any IT service running in the hybrid cloud within seconds. Learn top Veeam advantages over legacy backup and get Veeam for the price of your renewal

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The article explains the protocols and technology which is involved when two computers on different TCP/IP networks communicate with each other. In the diagram, a router is used to segregate two networks. The networks are 192.168.1.0/24 and 192…
Please see preceding article here: http://www.experts-exchange.com/Networking/Operating_Systems/A_11209-Root-Bridge-Election.html Figure 1 After Root Bridge has been elected, then what?..... Let's start by defining a Root Port in la…
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
Suggested Courses

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question