Solved

track down the location of a machine advertising a domain or workgroup

Posted on 2008-06-24
6
190 Views
Last Modified: 2010-04-21
Under Microsoft Windows Network I can see a Domain or Workgroup listed that shouldn't be. I can't access it. I would like to track it down. How do I go about finding what machine is advertising this?
0
Comment
Question by:jjc_mn
  • 3
  • 2
6 Comments
 
LVL 4

Accepted Solution

by:
raymondzwarts earned 500 total points
ID: 21859659
Use a packet capturing tool (like wireshark) to see who is broadcasting as master browser for the specific domain/workgroup. The packets will show up as Windows Browser Protocol and Server Message Block protocol packets.

The Packets will contain the Workgroup/Domain name and the source IP is the PC/Laptop/Server announcing the rougue domain/workgroup.

The broadcast is limited to the layer 2 subnet that the pc is on. But if you are using WINS or likewise systems in Active Directory it might take some more time to find the culprit.

Regards,
Raymond Zwarts
0
 
LVL 77

Expert Comment

by:Rob Williams
ID: 21859953
You should be able to get some information from a command line. Use DomainABC as an example domain name:
  nbtstat  -a  DomainABC
Should return a NetBIOS name list which should include a few entries such as:
ComputerName  <00>  UNIQUE
DomainABC         <00>   GROUP
It will also include the MAC address

Then ping the computer name:
     ping ComputerName
and it should return the IP address

Just a start. but it may help if you know the computer name ,MAC, and IP
If you do not get a response from the nbtstat command, or ping, it may be that the machine was temporarily connected to the network, and is no longer present. If that is the case the entry should disappear after a day or so.
0
 

Author Comment

by:jjc_mn
ID: 21867270
nbtstat -a DoaminABC doesn't work.  Is the example correct?

I haven't had a change to try wireshark yet.

0
Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

 
LVL 77

Expert Comment

by:Rob Williams
ID: 21867338
I assume you changed DomainABC to the domain name you are seeing. If it doesn't work it may have a firewall blocking the necessary ports, or possibly more likely it is no longer connected to the network.
0
 

Author Comment

by:jjc_mn
ID: 21867983
I did change the name. I didn't add any slashes, just the name. Does that matter. I am doing this at a workstation, not on a server. There should be no firewall and I do see them in the GUI  Under Microsoft Windows Network.

Can you past an example?
0
 

Author Closing Comment

by:jjc_mn
ID: 31470290
Thanks
0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This article is in response to a question (http://www.experts-exchange.com/Networking/Network_Management/Network_Analysis/Q_28230497.html) here at Experts Exchange. The Original Poster (OP) requires a utility that will accept a list of IP addresses …
A common practice in small networks is making file sharing easy which works extremely well when intra-network security is not an issue. In essence, everyone, that is "Everyone", is given access to all of the shared files - often the entire C: drive …
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…

860 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question