08-31-2010 12:54 AM
About a month ago we migrated out CiscoWorks server to VMware. Ever since we have had a significant amount of broadcast traffic coming from the server. We have noticed this as it is stopped by our firewall.
This traffic is broadcast on UDP port 44342 and 42342
There is also broadcast traffic to the subnet of the server on UDP port 137
From nbstat I can see that this traffic is coming from Internetwork Performance Monitor.
The traffic follows an interesting pattern in that for about 3 days after the server is rebooted it appears constantly then stops completely. After the next reboot the traffic appears again.
Is there anything that can be done to stop this traffic without stopping IPM from working?
09-01-2010 09:17 PM
Why do you think IPM is sending this traffic? UDP port 137 is used by Windows for the NetBIOS name service (i.e. resolving NetBIOS names to IP). I don't see how IPM would need to do a lot of lookups. However, something like Campus UT may do this when it runs acquisition if the end hosts do not have entries in DNS.
09-09-2010 01:43 AM
After seeing the traffic hit our firewall I did a netstat on the Cisco Works server and found traffic on UDP ports 44342 & 42342 from the process osiagent.exe. Through services I traced this back to the Cisco Works services.
I have seen a post which says this is COBRA agent advertisement traffic. It this so?
If so what exactly is the role of the COBRA agent and can it be administered?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide