Great Circle Associates Firewalls
(October 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: UDP 137
From: gary flynn <gary @ habanero . jmu . edu>
Date: Thu, 3 Oct 1996 16:41:18 -0400
To: firewalls @ greatcircle . com

I'm seeing lots of access violations for UDP 137 which is
used by Netbios name services. I'm blocking 137-139 from
the Internet. What I don't understand is why these are trying to
come in from the Internet destined for machines all over 
campus...some that aren't even running Netbios services (or so 
I'm told).

Going through RFC1001 and 1002 (quickly, I'm afraid) it seems
that these packets would be used to challenge a name. Why
would computers from sites all over the world be challenging
end user computers here?

One of the sites sending the packets was a Web site and I thought
maybe it did that because it was an NT based server or something but
I checked with the person whose PC was the target and they'd never
heard of the Web site (no it wasn't one that they'd publicly deny :-)

Of course, I might be misunderstanding the protocol and perhaps the
Internet is supporting Netbios broadcast service which means
its supporting a whole bunch of machines broadcasting their
names. Tell me this isn't true! Appletalk on the Internet :-)

Can someone explain this to me?

thanks,

Gary Flynn
Network Manager
James Madison University

Indexed By Date Previous: Need volunteer FTP archive site to host new security software
From: Marc Chatel <mchatel @ dial . oleane . com>
Next: RE: How does one set a rule in IBM's Internet Secure Network Gateway to allow Notes 4.1.4 replication?
From: Gene Lee <genel @ inforamp . net>
Indexed By Thread Previous: Re: BoS: Need volunteer FTP archive site to host new security software
From: Dan Stromberg <strombrg @ hydra . acs . uci . edu>
Next: UDP 137
From: Graham Dougall <Graham_Dougall @ manulife . com>

Google
 
Search Internet Search www.greatcircle.com