How do I trace ICMP packets to the Windows process that is sending them?
Posted on 2007-04-11
I've got a system sending large ICMP packets that our firewall is detecting. This is not a major issue but they are oversized and are fragmenting. Which seems odd. They appear to be transmitted at somewhat regular intervals.
I would like to dertermine what process is generating these packets. I've seached and found suggestions but no program or tool that is comparable to TCPView. Which is really what I'd like to see. I am a network administrator and compiling code on Windows is something I would like to avoid if possible. Ideally a pre-exisiting program to resolve this would be great.
Does anyone have a solution or suggestion on how to trace what process is sending these large ICMP packets?
I actually have 2 systems doing this: Windows 2000 Server, SP4 and Windows Server 2003 Standard.
-Wireshark does not tie packets to a process.
-TCPView does not sho ICMP traffic.
-I wonder if this is even possible.