davidshere
December 17th, 2008, 12:03 PM
We recently moved a server from outside our firewall to inside. Our firewall logs now show this box sending traffic to a destination port 11 on two internal devices. One is a switch and the other is another server. Here is a sample from the firewall log:
12/17/2008 00:27:23.160 - Notice - Network Access - UDP packet dropped - ***.***.***.***, 34257, X2, source.server.name - ***.***.***.***, 53, X0, destination.server.name - UDP DNS (Name Service) UDP 11 (DMZ->LAN)
My question is: How can I find out what application or process on the source server is sending this traffic?
12/17/2008 00:27:23.160 - Notice - Network Access - UDP packet dropped - ***.***.***.***, 34257, X2, source.server.name - ***.***.***.***, 53, X0, destination.server.name - UDP DNS (Name Service) UDP 11 (DMZ->LAN)
My question is: How can I find out what application or process on the source server is sending this traffic?