- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-26-2020 10:38 AM
After installing and connecting to Global Protect, FW policy logs are showing large amounts of UDP 137 getting blocking from Global Protect clients going to many random Public IP's. Any idea what would cause this? Public IP's have been MS, AWS, Google owned.
08-26-2020 11:51 AM
A little more information:
This only seems to happen when global protect client is active, and doesn't happen on all clients.
The UDP 137 traffic is Net Bios Name Query (Appears to be reverse lookup)
Name query NBSTAT *<00><00><00><00><00><00><00><00><00><00><00><00><00><00><00> to random Public IP's
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!