Solved

Netbios-NS packet capture

Posted on 2011-02-16
6
1,456 Views
Last Modified: 2012-05-11
I am using Wireshark to capture network traffic from an Windows XP workstation that makes an HTTPS conection to a remote host.   In the packet capture I can see Netbios name query broadcasts to the remote host.  I was hoping the packet capture would also show me what name the query was being performed against but the packet just shows zeros.   Is there a way for me to determine what name was queried?

Capture.PNG
0
Comment
Question by:AManoux
  • 4
  • 2
6 Comments
 
LVL 12

Accepted Solution

by:
Sommerblink earned 250 total points
ID: 34914103
Well.

The fact that you see NetBIOS queries going from the client to the server is telling me that you have a DNS problem.

In the real-world (eg: going to www.google.com, etc), you do not rely on NetBIOS for any name resolution.

Typically, when Windows (especially any version of windows which is still actively supported by Microsoft) resorts to NetBIOS for name resolution... it means that your client has no other way to resolve the name. (Please see http://www.microsoft.com/downloads/en/details.aspx?FamilyID=c76296fd-61c9-4079-a0bb-582bca4a846f, chapter 7)

So, besides the fact that you are seeing a NetBIOS packet while attempting to go to a website, what else is wrong?
0
 
LVL 1

Author Comment

by:AManoux
ID: 34918929
Thanks Sommerblink.
I agree, I have a feeling there is a DNS issue going on but I don't know where to start troubleshooting without knowing what host name the XP machine is having trouble with.  If I can't find out the host name via the Netbios request, how else can I determine it?
Everything is functioning with the HTTPS request to the website and the website page being accessed.  It just hangs for 3-5 seconds while the Netbios name lookup occurs and then times out.  
0
 
LVL 1

Author Comment

by:AManoux
ID: 34919398
Attaching more of the Wireshark capture for added information
Capture2.PNG
0
Easy, flexible multimedia distribution & control

Coming soon!  Ideal for large-scale A/V applications, ATEN's VM3200 Modular Matrix Switch is an all-in-one solution that simplifies video wall integration. Easily customize display layouts to see what you want, how you want it in 4k.

 
LVL 12

Expert Comment

by:Sommerblink
ID: 34982812
Sorry for the delay.

Anyway, you can try to simply disable NetBIOS on that network card / network connection (if its VPN or whatnot).

Simply go to the network card / network connection, go to properties, IPv4 properties, then go to the advanced button.

On the WINS tab, place a radio dot next to Disable NetBIOS over TCP/IP.

Let see if this makes your queries go away without breaking anything else.

If it does, then at least you've got some new information.
0
 
LVL 1

Assisted Solution

by:AManoux
AManoux earned 0 total points
ID: 34982922
Thanks for getting back to me.  Sine my last post I belive I've discovered the cause of the issue.
Client SSL implementations often try to reverse DNS lookup the IP of the connection to try and validate the DN of the certificate presented during the SSL handshake.  Because there was no PTR DNS record for the hostname my client dropped back to using Netbios broadcasts. The lack of the PTR record didn't stop the SSL connection from occuring, it just slowed it down at the beginning while it tried to resolve the certificate host name.  
0
 
LVL 1

Author Closing Comment

by:AManoux
ID: 35015566
Solved my own issue
0

Featured Post

Connect further...control easier

With the ATEN CE624, you can now enjoy a high-quality visual experience powered by HDBaseT technology and the convenience of a single Cat6 cable to transmit uncompressed video with zero latency and multi-streaming for dual-view applications where remote access is required.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
WAN and LAN NIC on Windows Server 2012 11 126
restore DAG configuration 1 42
software license audit 6 75
How do I make our RDS server available from the Internet 5 61
Greetings, Experts! First let me state that this website is top notch. I thoroughly enjoy the community that is shared here; those seeking help and those willing to sacrifice their time to help. It is fantastic. I am writing this article at th…
We recently endured a series of broadcast storms that caused our ISP to shut us down for brief periods of time. After going through a multitude of tests, we determined that the issue was related to Intel NIC drivers on some new HP desktop computers …
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

790 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question