Solved

Netbios-NS packet capture

Posted on 2011-02-16
6
1,481 Views
Last Modified: 2012-05-11
I am using Wireshark to capture network traffic from an Windows XP workstation that makes an HTTPS conection to a remote host.   In the packet capture I can see Netbios name query broadcasts to the remote host.  I was hoping the packet capture would also show me what name the query was being performed against but the packet just shows zeros.   Is there a way for me to determine what name was queried?

Capture.PNG
0
Comment
Question by:AManoux
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
6 Comments
 
LVL 12

Accepted Solution

by:
Sommerblink earned 250 total points
ID: 34914103
Well.

The fact that you see NetBIOS queries going from the client to the server is telling me that you have a DNS problem.

In the real-world (eg: going to www.google.com, etc), you do not rely on NetBIOS for any name resolution.

Typically, when Windows (especially any version of windows which is still actively supported by Microsoft) resorts to NetBIOS for name resolution... it means that your client has no other way to resolve the name. (Please see http://www.microsoft.com/downloads/en/details.aspx?FamilyID=c76296fd-61c9-4079-a0bb-582bca4a846f, chapter 7)

So, besides the fact that you are seeing a NetBIOS packet while attempting to go to a website, what else is wrong?
0
 
LVL 1

Author Comment

by:AManoux
ID: 34918929
Thanks Sommerblink.
I agree, I have a feeling there is a DNS issue going on but I don't know where to start troubleshooting without knowing what host name the XP machine is having trouble with.  If I can't find out the host name via the Netbios request, how else can I determine it?
Everything is functioning with the HTTPS request to the website and the website page being accessed.  It just hangs for 3-5 seconds while the Netbios name lookup occurs and then times out.  
0
 
LVL 1

Author Comment

by:AManoux
ID: 34919398
Attaching more of the Wireshark capture for added information
Capture2.PNG
0
Will your db performance match your db growth?

In Percona’s white paper “Performance at Scale: Keeping Your Database on Its Toes,” we take a high-level approach to what you need to think about when planning for database scalability.

 
LVL 12

Expert Comment

by:Sommerblink
ID: 34982812
Sorry for the delay.

Anyway, you can try to simply disable NetBIOS on that network card / network connection (if its VPN or whatnot).

Simply go to the network card / network connection, go to properties, IPv4 properties, then go to the advanced button.

On the WINS tab, place a radio dot next to Disable NetBIOS over TCP/IP.

Let see if this makes your queries go away without breaking anything else.

If it does, then at least you've got some new information.
0
 
LVL 1

Assisted Solution

by:AManoux
AManoux earned 0 total points
ID: 34982922
Thanks for getting back to me.  Sine my last post I belive I've discovered the cause of the issue.
Client SSL implementations often try to reverse DNS lookup the IP of the connection to try and validate the DN of the certificate presented during the SSL handshake.  Because there was no PTR DNS record for the hostname my client dropped back to using Netbios broadcasts. The lack of the PTR record didn't stop the SSL connection from occuring, it just slowed it down at the beginning while it tried to resolve the certificate host name.  
0
 
LVL 1

Author Closing Comment

by:AManoux
ID: 35015566
Solved my own issue
0

Featured Post

Create the perfect environment for any meeting

You might have a modern environment with all sorts of high-tech equipment, but what makes it worthwhile is how you seamlessly bring together the presentation with audio, video and lighting. The ATEN Control System provides integrated control and system automation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Have you ever set up your wireless router at home or in the office to find that you little pop-up bubble in the bottom right-hand corner of Windows read "IP Conflict - One of more computers on the network have been assigned the following IP address"…
A common practice in small networks is making file sharing easy which works extremely well when intra-network security is not an issue. In essence, everyone, that is "Everyone", is given access to all of the shared files - often the entire C: drive …
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…
Michael from AdRem Software outlines event notifications and Automatic Corrective Actions in network monitoring. Automatic Corrective Actions are scripts, which can automatically run upon discovery of a certain undesirable condition in your network.…
Suggested Courses
Course of the Month7 days, 13 hours left to enroll

632 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question