cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
705
Views
5
Helpful
3
Replies

NetBIOS (UDP 137) causing "noise" in PIX Syslog

cdoyle
Level 1
Level 1

Our PIX logs are loaded with deny reports regarding udp port 137 traffic coming from our Win Servers, it's making it difficult at times to spot other deny messages we need to be investigating.

Disabling NetBIOS over TCP/IP on the Servers is unfortunately not an option for us in this particular VLAN. The underlying infrastructure is a Catalyst 6500 Switch and we are wondering if there is a way, using its feature set, to filter the traffic inbound to the PIX's port. We would like to block UDP/137 at the port therefore dropping the unwanted packets before the PIX even sees them.

We've looked into VACLs but are only aware of their ability ACL on MAC address, not higher level traffic. Being this PIX interface and the Servers are in the same Layer2 VLAN, we don't have a Layer3 interface we can leverage to apply an ACL to.

Is anyone else dealing with this issue, any suggestions?

1 Accepted Solution

Accepted Solutions

tvanginneken
Level 4
Level 4

Hi,

to make the logging op NetBios disappear, you have the possibility to create an access list entry that matches the netbios traffic and disables logging for that entry. At the end of the access-list entry just add "log disable".

This feature requires PIX OS v6.3.

Kind Regards,

Tom

View solution in original post

3 Replies 3

tvanginneken
Level 4
Level 4

Hi,

to make the logging op NetBios disappear, you have the possibility to create an access list entry that matches the netbios traffic and disables logging for that entry. At the end of the access-list entry just add "log disable".

This feature requires PIX OS v6.3.

Kind Regards,

Tom

Hi,

I have same problem with Pix 6.2.

Any ideas?

Thank-you for your information Tom !

We plan to take your advice and upgrade to 6.3 in order to implement this solution.

Thanks again !

Craig

Review Cisco Networking products for a $25 gift card