10-29-2003 10:38 AM - edited 03-09-2019 05:19 AM
Recently, I've been seeing a lot of 2152 ICMP Flood traffic generated from workstations to a DNS/Active Directory server. I checked the workstations and they are clean of virus/trojan/malicous users/etc..., I enabled packetcapture, but see nothing unusual in etherreal. Maybe someone can help analyze the packet?
Thanks
10-29-2003 11:37 AM
Sure, if you would forward the packet to me I would be glad to take a look at it. (klwiley@cisco.com)
You mention that you are seeing the traffic from the workstations to the server. How many workstations are involved? Are they all on the same network segment?
You also say you ttok a look at the worksations, but did you also give the serve in question a once over?
KLW
10-29-2003 09:38 PM
Don't believe this would be virus/trojan...because it is only banging against one server. drop down to a command prompt on the WS and issue the netstat -a command and look at what ports/protos are open, and look for the port that is using ICMP. This should get you where you want to go? Let me know. Thanks.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide