Re: NIC always stays on...how to track traffic in Windows 2003

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



yes.

--
Regards,
Andrei Ungureanu
www.eventid.net
Test our new EventReader!
http://www.altairtech.ca/eventreader/default2.asp?ref=au

"Thomas" <thomas.trinh@xxxxxxxxx> wrote in message
news:%2357BHeDhGHA.3924@xxxxxxxxxxxxxxxxxxxxxxx
Hi Andrei

I used netstat -na and found out there are some connections to external
IPs that uses port 25. The state was ESTABLISHED. I'm running IIS SMTP
server (for sending out emails from our software) on the box, does that
mean my SMTP is making connections to remote email servers?

Tom


"Andrei Ungureanu" <contact me via www.itboard.ro> wrote in message
news:uOmP4YreGHA.3456@xxxxxxxxxxxxxxxxxxxxxxx
or you can use <netstat -na> to see the connections from your computer.
Based on the netstat output you can see who is the remote computer and
what port is used.

--
Regards,
Andrei Ungureanu
www.eventid.net
Test our new EventReader!
http://www.altairtech.ca/eventreader/default2.asp?ref=au

"ajpra" <ajpra@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:2C31ED00-84E7-42DE-B9EB-82EF7973EFDF@xxxxxxxxxxxxxxxx
Hello Thomas,

I could certainly have a look at the netmon trace. Please mail the
capture
file to ajayprk@xxxxxxxxxx Also please mention the ip address of the
machine
on which this trace was taken, along with the roles of this machine i.e.
DC,
DNS, DHCP etc.

I will let you know if i come across anything unusual.

Regards,
Ajay Prakash


"Thomas" wrote:

Hi Ajay,

Thanks for the help. I captured the Monitor log and saved it. After
viewing the log, I still can't decipher if my server is sending
legitimate
traffic. If it's possible, you think I could email you the capture
file?

Please email me at sfaryu@xxxxxxxxxxx if you think you can help me out.
Thanks.

Tom

"ajpra" <ajpra@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:C48A2733-EB9D-4CDD-BB36-086BD9346E2E@xxxxxxxxxxxxxxxx
Hello,

You can install and run the network Monitor tool (included in 2003
setup
cd). This tool can be installed through Add remove programs -> add
remove
windows components. This tool will capture all the network traffic
leaving
and coming to your machine including ip addresses, ports and type of
data
that is flowing.

When you run network monitor tool for the first time, it will ask you
for
the interface on which it should be run. Choose your Local Area
Connection
on
which you are seeing the network activity. Also increase the buffer
size
from
the capture menu to at least 5 megs. Run the trace for about 5
minutes and
then stop and view the capture. It will list all network traffic
originiting
and coming to your machine.

If you need further help in reading the traces, please let me know.

Regards,
Ajay Prakash

"Thomas" wrote:

Hi,

I have a W2K3 server that has a NIC that is always on (meaning data
are
being transferred). Double clicking the NIC, I see the received and
sent
packet counter keeps increasing every second.

Is there anyway in Windows natively to track what program or
services are
sending those packets? I'm using the Performance counter right now,
but
it
doesn't tell me much.

TIA

Tom












.



Relevant Pages

  • Re: NIC always stays on...how to track traffic in Windows 2003
    ... that uses port 25. ... I'm running IIS SMTP server ... you think I could email you the capture ... When you run network monitor tool for the first time, ...
    (microsoft.public.win2000.networking)
  • Re: Capturing NEMA Data from a GPS
    ... log so that when I'm sailing the GPS will create a log for me every 15 ... Click the pick arrow under "Connect using" and pick your COM port. ... To start reading the NMEA data, just click the little telephone to ... If you click TRANSFER then CAPTURE TEXT you can store ...
    (rec.boats.electronics)
  • Capturing Error!
    ... not what to do video capture. ... up to the computer via firewire using my 6 pin firewire ... port from my Sound Blaster Audigy PCI card. ... my camera worked fine and capture video didnt have any ...
    (microsoft.public.windowsxp.moviemaker)
  • Re: NIC always stays on...how to track traffic in Windows 2003
    ... Based on the netstat output you can see who is the remote computer and what ... I could certainly have a look at the netmon trace. ... you think I could email you the capture file? ... When you run network monitor tool for the first time, ...
    (microsoft.public.win2000.networking)
  • RE: [Full-Disclosure] strange traffic ?
    ... so i cannot help you there, now have configured it to log all such traffic, will come back if i manage to capture any packet data ... and the initial connect attempt on port 139 is attack vertor. ... this used to occur only when i used to bring down sygate firewall... ... there are other firewalls that prevent the comprmise and the sinffer is capturing the data.... ...
    (Full-Disclosure)