Solved

The browser driver has received too many illegal datagrams

Posted on 2008-10-28
2
2,253 Views
Last Modified: 2012-06-27
<servername> : The browser driver has received too many illegal datagrams from the remote computer EHZW8CYGAI2OEJR to name <domain> on transport NetBT_Tcpip_{95A63A61-6884-4. The data is the datagram. No more events will be generated until the reset frequency has expired.

I am getting these every few days on my PDC in one of our Windows 2003 Domains.

We run one of the largest AD infrastructure on earth (according to Microsoft) with multiple forests. This particular error is from the child domain of our main user forest.

I have checked the PDC out and it is fine, well, in terms of AD there are no issues.

I am unsure what this error means as Microsoft say it could be an attack or maybe nothing more than dodgy nic drivers.

Anyone got any ideas?

We are running Win2k3 Forest Functional level on 64bit with SP1. It all runs on HP DL380's (G4's and G5's). None of the drivers have ever been updated from the original builds and no other servers are showing this error.
0
Comment
Question by:mickdoc
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 70

Assisted Solution

by:KCTS
KCTS earned 100 total points
ID: 22820183
Well I can't really add much to what you have already been told - faulty NICs and/or drivers could be responsible or you could be under attack - you could monitor the network and try and determine the source of the packets.
0
 
LVL 3

Accepted Solution

by:
mickdoc earned 0 total points
ID: 23956307
Hmmm... the problem went away on its own. Dunno what caused it to be honest.
0

Featured Post

Office 365 Advanced Training for Admins

Special Offer:  Buy 1 course, get 2nd free!  Buy the 'Managing Office 365 Identities & Requirements' course w/ Accelerated TestPrep, and automatically receive the 'Enabling Office 365 Services' course FREE!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Always backup Domain, SYSVOL etc.using processes according to Microsoft Best Practices. This is meant as a disaster recovery process for small environments that did not implement backup processes and did not run a secondary domain controller that ne…
Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question