12-07-2013 03:20 AM - edited 03-11-2019 08:14 PM
Hi,
I am getting lot of UDP request discarded from 10.145.0.66/138 to outside 10.145.0.255/138(Log message ID 710005).
I herewith attaching the config file.
Appreciate your early response.
Regards / Ramesh M
12-07-2013 03:57 AM
Hi,
As with your other discussion, this seems to be broadcast traffic related to Netbios that stops at the firewall as expected.
- Jouni
12-07-2013 05:33 AM
Hi
From where the traffic initiated/ reason for this error. Why this netbios traffic to be broadcat.
Also the source and destinations are in the same interface.
Please siggest
Regards / Ramesh M
12-07-2013 05:48 AM
Hi,
The traffic is initiated from the host mentioned in the log message (10.145.0.66) and the broadcast is naturally destined for the broadcast address (10.145.0.255) of that subnet as you can see from the log message also. The source and destination are naturally on the same network as broadcast traffic wont go beyond the first L3 hop (router hop) in the network.
I dont know the operation of Netbios enough to give you a good explanation but to my understanding in Windows host networks if no separate name server is used the operation is based on broadcast traffic.
In your case the ASA naturally sees this traffic as its broadcast traffic and drops it as expected.
- Jouni
12-07-2013 08:12 AM
Hi
Still I am gettng huge number of discard traffic,
Is any chance of port scanning/ attack/ botnet
12-07-2013 08:15 AM
Hi,
If you have your Windows host on a switch network and their gateway is the ASA then you will keep seeing these messages from multiple devices.
These messages are not port scanning. They are just typical broadcast traffic from the Windows hosts.
- Jouni
12-08-2013 12:36 AM
Hi,
Is it possible to disable the netbios port 137 and 138 on server. will it cause any impact.
Please suggest.
Regards / Ramesh M
12-08-2013 12:06 PM
Hello,
Are you using DHCP on your network?
You can do this via DHCP.
Or manually
This disables the SMB direct host listener on
Rate all of the helpful posts!!!
Regards,
Jcarvaja
Follow me on http://laguiadelnetworking.com
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide