?
Solved

Exchange server sending strange traffic - UDP ports

Posted on 2009-07-09
5
Medium Priority
?
544 Views
Last Modified: 2012-05-07
I am seeing some really strange things on my network.  According to my firewall logs, it looks as if my exchange server is attempting to connect to random IP addresses in the private network ranges that are outside of my internal private network ranges.  The only commonality is what ports the Exchange system is sending out on.  I see the traffic on port 1418, 1475, 1659, and a couple other ports.  The issue started towards the end last month, around the 25th if I am not mistaken.  As far as I am aware, there have been no updates or software packages recently installed on this system.  I cannot find any processes that would be causing these issues either.  My virus definitions are up to date, and there was a full system scan run this past Sunday without any issues found&  I have run WireShark on the Exchange server and I see the traffic in the packet capture.  I need to get this resolved ASAP.
0
Comment
Question by:warewols
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 12

Assisted Solution

by:marcustech
marcustech earned 1600 total points
ID: 24813532
try run

netstat -b -v
to show the process that a creating the connections.

If that doesn't shed any light on the situation, post them here and I'll have a look for you.

Exchange shouldn't be making any UDP connections.
0
 
LVL 12

Assisted Solution

by:marcustech
marcustech earned 1600 total points
ID: 24813535
(run that from CMD on the server - I forgot to mention)
0
 

Author Comment

by:warewols
ID: 24813754
I have attached the netstat command's output.  I am going through it myself right now...  Thanks for your help.
info.txt
0
 
LVL 2

Assisted Solution

by:TimMallery
TimMallery earned 400 total points
ID: 24822387
Are you using EMC Legato Software? Some of this traffic seems associated with that.
0
 

Accepted Solution

by:
warewols earned 0 total points
ID: 24823899
After talking to Microsoft last night, this is a normal operation of the email server.  The port that I was seeing is just an arbitrary port that was chosen on the server for email traffic, on the the servers chose 1418 (assigned to Timbuktu in the RFC listings) to start the store.exe process.  Store.exe picks a port by finding the next available open port that is above port number 1024.

The reason we are seeing the traffic appear in the logs is because of malformed packets coming from the clients attempting to connect to the email server.  We are seeing the traffic coming in on a valid IP address (internal and external) and then attempting to go out to a private IP address outside the range of the internal private IP addresses.  The tech from Microsoft stated that these malformed packets could be coming from anywhere that has a NAT translation in place.  Some of the packets we inspected that were going to the unusual IP addresses showed MAC addresses for AirPort wireless APs, a Sonic firewall, and also a LINKSYS router.
0

Featured Post

On Demand Webinar - Networking for the Cloud Era

This webinar discusses:
-Common barriers companies experience when moving to the cloud
-How SD-WAN changes the way we look at networks
-Best practices customers should employ moving forward with cloud migration
-What happens behind the scenes of SteelConnect’s one-click button

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Check out this step-by-step guide for using the newly updated Experts Exchange mobile app—released on May 30.
A couple of months ago we ran into an issue that necessitated re-creating our Edge Subscriptions. However, when we attempted to execute the command: New-EdgeSubscription -filename C:\NewEdgeSub_01.xml we received an error indicating that the LDAP se…
In this video we show how to create a Shared Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Sha…
how to add IIS SMTP to handle application/Scanner relays into office 365.
Suggested Courses
Course of the Month12 days, 23 hours left to enroll

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question