Many windows 7 workstations on the LAN have full security event logs. The issue is from many netBIOS broadcasts that are being blocked by the Windows firewall and then logged as an Audit Failure.
Why are all workstations broadcasting to each other so much that the logs are filling?
Is the broadcasting normal behavior?
Will it break the network if I disable or block netBIOS from all workstations? I do use the c$ share remotely.
Possibly the firewall shouldn't be blocking this?
Tons of questions because I want to understand this behavior. Thanks!
The Windows Filtering Platform has blocked a packet.
Process ID: 4
Application Name: System
Source Address: 192.168.88.54
Source Port: 138
Destination Address: 192.168.88.255
Destination Port: 138
Filter Run-Time ID: 635422
Layer Name: Receive/Accept
Layer Run-Time ID: 44