Re: DC floods LAN

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



In news:8319A987-42B5-4978-B000-D9B52BA7FACA@xxxxxxxxxxxxx,
sir-bob <sirbob@xxxxxxxxxxxxxxxxxxxxxxxxx>, posted the following:
Hi All:

Hope this is the correct forum for this post.

We have experienced the following problem on a number of occasions
now and up until this point have not found a solution.

After patching a Server 2003 R2 Domain Controller and rebooting the DC
essentially runs a DOS on the LAN. After a reboot the problem clears
again. I have captured this traffic on one of the DC's that caused
this problem. The capture showed thousands of packets per second.

The packets were all UDP from the DC to 224.0.1.24, the source and
destination port was 42.

Has anyone else experienced this or perhaps know what the cause may
be?

Thanks
SB

I have not seen this, but FYI, TCP and UDP port 42 are the WINS replication ports. WINS uses these ports for communication between replication partners. And IP 224.0.0.0 through 239.255.255.255 is the multicast range.

Are you using WINS? If so, do you have more than one WINS server? If so, are they replication partners?

If WINS is not installed, can use netstat, or TCPView (free download) to identify which exe is broadcasting.

Do you remember which patch was installed that you believe started the broadcasts?

--
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSA Messaging, MCT
Microsoft Certified Trainer
aceman@xxxxxxxxxxxxxxxxxxxxxxx

For urgent issues, you may want to contact Microsoft PSS directly. Please
check http://support.microsoft.com for regional support phone numbers.

.



Relevant Pages

  • Re: Disable "Receive all incoming beams"
    ... broadcasting the message in the archives of this group:- ... > beams" so that I can use the OpenNETCF port. ... > Below shows the registry entry I am looking at. ... I look at the registry with a RegEdit utility and it shows the ...
    (microsoft.public.dotnet.framework.compactframework)
  • Re: Virtualized VPN
    ... If you want to port forward PPTP VPN traffic, you need to forward TCP 1723 as well as GRE or Protocol ID 47. ... Theres's two parts of it, the L2TP traffic uses UDP Port 1701, and the IPSec traffic requires the following: UDP Port 500, Protocol ID 50 and Protocol ID 51. ... Microsoft Certified Trainer ...
    (microsoft.public.windows.server.networking)
  • Re: Broadcasting on port 31337? - RESOLVED
    ... On Monday 09 May 2005 14:14, Richard Crawford wrote: ... > Our IT guy tells me that my Linux laptop is broadcasting on port 31337. ...
    (Fedora)
  • Re: setting up FTP
    ... I also have the FTP server to accept PASV or PORT. ... On the client side, such as using Cute, Bulletproof, FlashFXP, etc, I setup a session entry, then uncheck PASV, and it works nicely. ... Microsoft Certified Trainer ...
    (microsoft.public.windows.server.networking)
  • Re: Broadcasting on port 31337?
    ... On Mon, 9 May 2005, Richard Crawford wrote: ... > Our IT guy tells me that my Linux laptop is broadcasting on port 31337. ...
    (Fedora)