- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-09-2012 10:19 AM
All,
We've noticed some strange traffic patterns coming from our Agent boxes and am curious why, and if others are seeing something similar... ?
Looking in our Monitoring logs I see our two Agents sending data to:
14.1.1.19
14.2.1.19
14.2.1.1
Via SMB ports 135,137,139
This appears to be something out of Australia
We're blocking this communication, and they're fresh boxes with Anti-Virus installed so it's really odd that we're seeing this..
Anyone?
Thanks!
-Steve
05-09-2012 02:49 PM
What is your settings your of userid agents?
I think its recommended to disable netbios lookups but enable wmi lookups (if possible).
You can also in the menu enable debug log level and then watch the userid directory in program files and then copy the debug file as soon as you see this traffic (dont forget to change log level back to informational or such after you copied the debug log to not run out of disk).
Hopefully you can then find in the debuglog from where these ip addresses is pickedup (is it someone logging in to your exchange server or is it something else).
05-10-2012 01:37 AM
Hello,
UserAgents have a feature that scans workstations via WMI/Netbios. If you firewall request informations about an IP to a UserAgent (even if that IP is on internet), it will scan it.
If you don't want internet addresses to be scanned or IDed, look at your zone User Identification configuration and UserID doc in general.
05-11-2012 10:48 AM
We did have our Agents set to use Netbios so I disabled it, and now it seems to have quited down.
As far as zone ID goes we're only checking for IDs on our Trusted segment, IE: Trusted (Inside) -> Untrusted (Outside) -> Internet and not the reverse..
It's strange that those couple hosts would keep coming up... Hmmm..
Thanks guys!
-Steve
05-11-2012 12:02 PM
If im not mistaken you can in the userid agent also filter which ip addresses it should lookup/handle.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!