Hi All,
Let me start out by saying up front that I am a newbie. I have read many of y'all's posts and many of them have already helped me a lot. I work for a small business as a network administrator, and am still at the low end of the learning curve.![]()
We have a hardware SonicWall (which I am still trying to learn all the features), and I have been reviewing the firewall and IDS logs. About half of the traffic is from one of two IPs talking to port 138 (NetBios DGM). We are running DHCP on a Windows Server 2000 with XP computers on the network. We aren't running any applications on the network that would create such traffic (I don't know what more you might need to know to help me out).
Here's my questions: Is this traffic normal? What is it doing? Should I be concerned?




Reply With Quote