Link to home
Start Free TrialLog in
Avatar of Roccat
RoccatFlag for United States of America

asked on

Lots of multicast traffic from server

We have a windows server 2008 that runs a student information database.  Wire shark shows almost 100 packets a second going to a multicast address 224.0.0.150.  Any idea what this might be?  I am not great with networking so pardon my ignorance of the issue.
ASKER CERTIFIED SOLUTION
Avatar of Bill Bach
Bill Bach
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Roccat

ASKER

Port 150 UDP
Avatar of Roccat

ASKER

5478      64.496129      192.25.205.238      0      224.0.0.150      150 → 150  Len=583      UDP      00:50:56:ac:57:8a      00:50:56:ac:57:8a      192.25.205.238      625

This is the packet summary that is reoccurring about 100 times a second.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Roccat

ASKER

The tomcat 6 process is using 26 gb of ram right now.
Netbios is not disabled
Did a quick web search, and found this scary reference:

Port(s)       Protocol       Service       Details       Source
150       tcp,udp       sql-net       Denial of service of Ascend routers through port 150 (remote administration).
References: [CVE-1999-0221]
SQL-NET (IANA official)

Is it possible that the server is infected?  Were you able to see the process name via ProcMon?
So you are using NetBIOS with the Tomcat?
The UDP Port 150 is commonly used by NetBIOS
If you need it, then leave it running, but if not, the problem might disappear once it is disabled.
Maybe the cluster configuration in the Tomcat is not set properly.
It normally is set to a frequency of 500MS maybe it is somehow set to 5 or something like that.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Roccat

ASKER

Multiple reoccurring scheduled tasks that were failing were putting sending out all the traffic.  Not sure what they are broadcasting but it has calmed down for now.  Thank you for the help.
Avatar of Roccat

ASKER

Thank you!