11-02-2006 02:49 PM - edited 03-09-2019 04:45 PM
I am getting thusands of error messages
on port 135,139-netbios and port 1433.what is the root cause for this.
3|Nov 02 2006 23:39:18|106011: Deny inbound (No xlate) tcp src Wm:10.161.67.57/3064 dst Wm:10.161.72.238/135
11-02-2006 03:54 PM
That looks like hacking port scans. This is pretty normal on the Internet, but your 10. addresses would indicate this is internal to your network? Did it just start? Is it scanning addresses sequentially? Is the source address always the same?
11-02-2006 05:46 PM
it's started 1 day back and it is increasing now.the src is from 3-4 adresses from same subnet.
11-02-2006 04:38 PM
It could also be that somehting is trying to connect to a SQL database using named pipes and it is not set up to allow it.
It may be that someone has SQL Enterprise Manager installed and it is scanning for databases on your network.
Tom S
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: