[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 72
  • Last Modified:

Lots of multicast traffic from server

We have a windows server 2008 that runs a student information database.  Wire shark shows almost 100 packets a second going to a multicast address 224.0.0.150.  Any idea what this might be?  I am not great with networking so pardon my ignorance of the issue.
0
Roccat
Asked:
Roccat
  • 5
  • 3
  • 2
  • +1
3 Solutions
 
Bill BachPresidentCommented:
Can you post a sample of the data itself?  Perhaps there is something inside there which will indicate its origin.  Also, is it going out through a specific port, either TCP or UDP?  You can use "NETSTAT -a -b" from an administrative command line to see which application is using that port.  If that doesn't help, then the SysInternals product ProcMon (www.sysinternals.com) will be able to show you which process is transmitting the messages.
0
 
RoccatAuthor Commented:
Port 150 UDP
0
 
RoccatAuthor Commented:
5478      64.496129      192.25.205.238      0      224.0.0.150      150 → 150  Len=583      UDP      00:50:56:ac:57:8a      00:50:56:ac:57:8a      192.25.205.238      625

This is the packet summary that is reoccurring about 100 times a second.
0
Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

 
awed1Commented:
This could have to do with Net BIOS Is it disabled throughout?
Check if the computer with the .238 address has it enabled.
0
 
RoccatAuthor Commented:
The tomcat 6 process is using 26 gb of ram right now.
Netbios is not disabled
0
 
Bill BachPresidentCommented:
Did a quick web search, and found this scary reference:

Port(s)       Protocol       Service       Details       Source
150       tcp,udp       sql-net       Denial of service of Ascend routers through port 150 (remote administration).
References: [CVE-1999-0221]
SQL-NET (IANA official)

Is it possible that the server is infected?  Were you able to see the process name via ProcMon?
0
 
awed1Commented:
So you are using NetBIOS with the Tomcat?
The UDP Port 150 is commonly used by NetBIOS
If you need it, then leave it running, but if not, the problem might disappear once it is disabled.
0
 
awed1Commented:
Maybe the cluster configuration in the Tomcat is not set properly.
It normally is set to a frequency of 500MS maybe it is somehow set to 5 or something like that.
0
 
Craig BeckCommented:
224.0.0.150 is an unassigned multicast address.  It has nothing to do with UDP port 150 though.

Can you post a wireshark log?
0
 
RoccatAuthor Commented:
Multiple reoccurring scheduled tasks that were failing were putting sending out all the traffic.  Not sure what they are broadcasting but it has calmed down for now.  Thank you for the help.
0
 
RoccatAuthor Commented:
Thank you!
0

Featured Post

Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

  • 5
  • 3
  • 2
  • +1
Tackle projects and never again get stuck behind a technical roadblock.
Join Now