Roccat
asked on
Lots of multicast traffic from server
We have a windows server 2008 that runs a student information database. Wire shark shows almost 100 packets a second going to a multicast address 224.0.0.150. Any idea what this might be? I am not great with networking so pardon my ignorance of the issue.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
5478 64.496129 192.25.205.238 0 224.0.0.150 150 → 150 Len=583 UDP 00:50:56:ac:57:8a 00:50:56:ac:57:8a 192.25.205.238 625
This is the packet summary that is reoccurring about 100 times a second.
This is the packet summary that is reoccurring about 100 times a second.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
The tomcat 6 process is using 26 gb of ram right now.
Netbios is not disabled
Netbios is not disabled
Did a quick web search, and found this scary reference:
Port(s) Protocol Service Details Source
150 tcp,udp sql-net Denial of service of Ascend routers through port 150 (remote administration).
References: [CVE-1999-0221]
SQL-NET (IANA official)
Is it possible that the server is infected? Were you able to see the process name via ProcMon?
Port(s) Protocol Service Details Source
150 tcp,udp sql-net Denial of service of Ascend routers through port 150 (remote administration).
References: [CVE-1999-0221]
SQL-NET (IANA official)
Is it possible that the server is infected? Were you able to see the process name via ProcMon?
So you are using NetBIOS with the Tomcat?
The UDP Port 150 is commonly used by NetBIOS
If you need it, then leave it running, but if not, the problem might disappear once it is disabled.
The UDP Port 150 is commonly used by NetBIOS
If you need it, then leave it running, but if not, the problem might disappear once it is disabled.
Maybe the cluster configuration in the Tomcat is not set properly.
It normally is set to a frequency of 500MS maybe it is somehow set to 5 or something like that.
It normally is set to a frequency of 500MS maybe it is somehow set to 5 or something like that.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Multiple reoccurring scheduled tasks that were failing were putting sending out all the traffic. Not sure what they are broadcasting but it has calmed down for now. Thank you for the help.
ASKER
Thank you!
ASKER