<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Netbios 137/138 through ASA- UDP request discard logs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/netbios-137-138-through-asa-udp-request-discard-logs/m-p/2370352#M307491</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still I am gettng huge number of discard traffic, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is any chance of port scanning/ attack/ botnet&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 07 Dec 2013 16:12:33 GMT</pubDate>
    <dc:creator>Ramesh M</dc:creator>
    <dc:date>2013-12-07T16:12:33Z</dc:date>
    <item>
      <title>Netbios 137/138 through ASA- UDP request discard logs</title>
      <link>https://community.cisco.com/t5/network-security/netbios-137-138-through-asa-udp-request-discard-logs/m-p/2370348#M307485</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am getting lot of UDP request discarded from 10.145.0.66/138 to outside 10.145.0.255/138(Log message ID 710005).&lt;/P&gt;&lt;P&gt;I &lt;SPAN style="font-size: 10pt;"&gt;herewith attaching the config file.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Appreciate your early response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards / Ramesh M&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:14:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netbios-137-138-through-asa-udp-request-discard-logs/m-p/2370348#M307485</guid>
      <dc:creator>Ramesh M</dc:creator>
      <dc:date>2019-03-12T03:14:27Z</dc:date>
    </item>
    <item>
      <title>Netbios 137/138 through ASA- UDP request discard logs</title>
      <link>https://community.cisco.com/t5/network-security/netbios-137-138-through-asa-udp-request-discard-logs/m-p/2370349#M307488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As with your other discussion, this seems to be broadcast traffic related to Netbios that stops at the firewall as expected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Dec 2013 11:57:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netbios-137-138-through-asa-udp-request-discard-logs/m-p/2370349#M307488</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-12-07T11:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: Netbios 137/138 through ASA- UDP request discard logs</title>
      <link>https://community.cisco.com/t5/network-security/netbios-137-138-through-asa-udp-request-discard-logs/m-p/2370350#M307489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From where the traffic initiated/ reason for this error. Why this netbios traffic to be broadcat.&lt;/P&gt;&lt;P&gt;Also the source and destinations are in the &lt;SPAN style="font-size: 10pt;"&gt;same interface.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please siggest&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards / Ramesh M&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Dec 2013 13:33:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netbios-137-138-through-asa-udp-request-discard-logs/m-p/2370350#M307489</guid>
      <dc:creator>Ramesh M</dc:creator>
      <dc:date>2013-12-07T13:33:02Z</dc:date>
    </item>
    <item>
      <title>Netbios 137/138 through ASA- UDP request discard logs</title>
      <link>https://community.cisco.com/t5/network-security/netbios-137-138-through-asa-udp-request-discard-logs/m-p/2370351#M307490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The traffic is initiated from the host mentioned in the log message (10.145.0.66)&amp;nbsp; and the broadcast is naturally destined for the broadcast address (10.145.0.255) of that subnet as you can see from the log message also. The source and destination are naturally on the same network as broadcast traffic wont go beyond the first L3 hop (router hop) in the network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont know the operation of Netbios enough to give you a good explanation but to my understanding in Windows host networks if no separate name server is used the operation is based on broadcast traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your case the ASA naturally sees this traffic as its broadcast traffic and drops it as expected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Dec 2013 13:48:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netbios-137-138-through-asa-udp-request-discard-logs/m-p/2370351#M307490</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-12-07T13:48:24Z</dc:date>
    </item>
    <item>
      <title>Netbios 137/138 through ASA- UDP request discard logs</title>
      <link>https://community.cisco.com/t5/network-security/netbios-137-138-through-asa-udp-request-discard-logs/m-p/2370352#M307491</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still I am gettng huge number of discard traffic, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is any chance of port scanning/ attack/ botnet&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Dec 2013 16:12:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netbios-137-138-through-asa-udp-request-discard-logs/m-p/2370352#M307491</guid>
      <dc:creator>Ramesh M</dc:creator>
      <dc:date>2013-12-07T16:12:33Z</dc:date>
    </item>
    <item>
      <title>Netbios 137/138 through ASA- UDP request discard logs</title>
      <link>https://community.cisco.com/t5/network-security/netbios-137-138-through-asa-udp-request-discard-logs/m-p/2370353#M307492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have your Windows host on a switch network and their gateway is the ASA then you will keep seeing these messages from multiple devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These messages are not port scanning. They are just typical broadcast traffic from the Windows hosts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Dec 2013 16:15:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netbios-137-138-through-asa-udp-request-discard-logs/m-p/2370353#M307492</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-12-07T16:15:25Z</dc:date>
    </item>
    <item>
      <title>Netbios 137/138 through ASA- UDP request discard logs</title>
      <link>https://community.cisco.com/t5/network-security/netbios-137-138-through-asa-udp-request-discard-logs/m-p/2370354#M307499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to disable the netbios port 137 and 138 on server. will it cause any impact.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please suggest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards / Ramesh M&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Dec 2013 08:36:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netbios-137-138-through-asa-udp-request-discard-logs/m-p/2370354#M307499</guid>
      <dc:creator>Ramesh M</dc:creator>
      <dc:date>2013-12-08T08:36:22Z</dc:date>
    </item>
    <item>
      <title>Netbios 137/138 through ASA- UDP request discard logs</title>
      <link>https://community.cisco.com/t5/network-security/netbios-137-138-through-asa-udp-request-discard-logs/m-p/2370355#M307501</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you using DHCP on your network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can do this via DHCP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or manually&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL style="font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 15px; margin: 0px 0px 1.625em 2.5em; vertical-align: baseline; color: #373737; line-height: 24px; background-color: #ffffff;"&gt;&lt;LI&gt;From the &lt;STRONG style="font-family: inherit; font-style: inherit; vertical-align: baseline;"&gt;Start&lt;/STRONG&gt; menu, right-click &lt;STRONG style="font-family: inherit; font-style: inherit; vertical-align: baseline;"&gt;My Computer&lt;/STRONG&gt;, and then click &lt;STRONG style="font-family: inherit; font-style: inherit; vertical-align: baseline;"&gt;Manage&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Expand &lt;STRONG style="font-family: inherit; font-style: inherit; vertical-align: baseline;"&gt;System Tools&lt;/STRONG&gt;, and then clear the &lt;STRONG style="font-family: inherit; font-style: inherit; vertical-align: baseline;"&gt;Device Manager&lt;/STRONG&gt; check box.&lt;/LI&gt;&lt;LI&gt;Right-click &lt;STRONG style="font-family: inherit; font-style: inherit; vertical-align: baseline;"&gt;Device Manager&lt;/STRONG&gt;, point to &lt;STRONG style="font-family: inherit; font-style: inherit; vertical-align: baseline;"&gt;View&lt;/STRONG&gt;, and then select &lt;STRONG style="font-family: inherit; font-style: inherit; vertical-align: baseline;"&gt;Show hidden devices&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Expand &lt;STRONG style="font-family: inherit; font-style: inherit; vertical-align: baseline;"&gt;Non-Plug and Play Drivers&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Right-click &lt;STRONG style="font-family: inherit; font-style: inherit; vertical-align: baseline;"&gt;NetBios over TCP/IP&lt;/STRONG&gt;, and then click &lt;STRONG style="font-family: inherit; font-style: inherit; vertical-align: baseline;"&gt;Disable&lt;/STRONG&gt;.&lt;/LI&gt;&lt;/OL&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 15px; margin: 0px 0px 1.625em; vertical-align: baseline; color: #373737; line-height: 24px; background-color: #ffffff;"&gt;This disables the SMB direct host listener on &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rate all of the helpful posts!!! &lt;BR /&gt; &lt;BR /&gt;Regards, &lt;BR /&gt; &lt;BR /&gt;Jcarvaja &lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Follow me on &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Dec 2013 20:06:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netbios-137-138-through-asa-udp-request-discard-logs/m-p/2370355#M307501</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-12-08T20:06:53Z</dc:date>
    </item>
  </channel>
</rss>

