After installing and connecting to Global Protect, FW policy logs are showing large amounts of UDP 137 getting blocking from Global Protect clients going to many random Public IP's. Any idea what would cause this? Public IP's have been MS, AWS, Google owned.
A little more information:
This only seems to happen when global protect client is active, and doesn't happen on all clients.
The UDP 137 traffic is Net Bios Name Query (Appears to be reverse lookup)
Name query NBSTAT *<00><00><00><00><00><00><00><00><00><00><00><00><00><00><00> to random Public IP's
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The Live Community thanks you for your participation!