Exchange server sending strange traffic - UDP ports
Posted on 2009-07-09
I am seeing some really strange things on my network. According to my firewall logs, it looks as if my exchange server is attempting to connect to random IP addresses in the private network ranges that are outside of my internal private network ranges. The only commonality is what ports the Exchange system is sending out on. I see the traffic on port 1418, 1475, 1659, and a couple other ports. The issue started towards the end last month, around the 25th if I am not mistaken. As far as I am aware, there have been no updates or software packages recently installed on this system. I cannot find any processes that would be causing these issues either. My virus definitions are up to date, and there was a full system scan run this past Sunday without any issues found& I have run WireShark on the Exchange server and I see the traffic in the packet capture. I need to get this resolved ASAP.