Solved

Large amount of DNS event 5501 in event logs

Posted on 2010-09-23
4
1,171 Views
Last Modified: 2013-12-05
I've got a 2000 Domain controller with a lot of 5501 events happening. The bad packets are coming from a particular IP, based in Austria.
I realise that the event is just informational, but I'm concerend that this one IP is maliciously sending malformed packets, and it's slowing down my DSN server.
Can anyone give me a good way to deal with it?
0
Comment
Question by:lineonecorp
  • 2
4 Comments
 
LVL 7

Accepted Solution

by:
Christopher Martinez earned 150 total points
ID: 33746185
Do you have a ACL/IPSec setup? If so i would make sure that this IP is filtered to ignore all request.

If you would lik emore info on doing this i suggest this article
http://support.microsoft.com/kb/813878
Good luck!
0
 
LVL 26

Assisted Solution

by:DrDave242
DrDave242 earned 150 total points
ID: 33755567
If the packets are all coming from one IP outside your network, and you have no idea what that IP is or why it would be sending those packets, you should consider blocking it at your firewall.  You should also consider upgrading that DC, as Windows 2000 reached end-of-life in July, so MS will no longer provide support for it.

0
 

Author Comment

by:lineonecorp
ID: 33772596
I will read the article and get back to you.
0
 

Author Closing Comment

by:lineonecorp
ID: 33775629
Thanks for the suggestions
0

Featured Post

The New “Normal” in Modern Enterprise Operations

DevOps for the modern enterprise offers many benefits — increased agility, productivity, and more, but digital transformation isn’t easy, especially if you’re not addressing the right issues. Register for the webinar to dive into the “new normal” for enterprise modern ops.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
AD backup 6 78
check if a sub domain uses a CNAME or A RECORD? 1 51
Windows Server 2012 R2 -- event log "NIGHTLY" summary ? 1 30
SPF record issue 6 53
A quick step-by-step overview of installing and configuring Carbonite Server Backup.
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
In a recent question (https://www.experts-exchange.com/questions/29004105/Run-AutoHotkey-script-directly-from-Notepad.html) here at Experts Exchange, a member asked how to run an AutoHotkey script (.AHK) directly from Notepad++ (aka NPP). This video…

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question