Great Circle Associates Firewalls
(October 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: UDP 137
From: Graham Dougall <Graham_Dougall @ manulife . com>
Date: 4 Oct 96 14:44:01 EDT
To: firewalls <firewalls @ GreatCircle . COM>

gary flynn <gary @
 habanero .
 jmu .
 edu> wrote:

> I'm seeing lots of access violations for UDP 137 which is
> used by Netbios name services. I'm blocking 137-139 from
> the Internet. What I don't understand is why these are trying to
> come in from the Internet destined for machines all over 
> campus...some that aren't even running Netbios services (or so 
> I'm told).

We are seeing violations for UDP 137 as well. 

At the same time as the violation we see the same IP address accessing our web 
site which is behind the firewall recording the violation. I suspect that the 
systems at these IP addresses have WINS and/or NETBIOS over IP enabled whether 
they know it or not. In our case the IP address causing the violations appear 
to ISPs, so I belive that these are dialup users. Thus, when accessing our web 
site, WINS on their system is confused and attempts to do WINS name resolution 
using the address of our web site/firewall.

E. Graham Dougall, CISSP, FLMI/ACS, I.S.P.
Manulife Financial  

Indexed By Date Previous: Re: async file transfers through firewall, how?
From: "Rick Owens" <rowens @ fvcc . cc . mt . us>
Next: Re: Gauntlet vs. Sidewinder
From: Richard Stiennon <richards @ netrex . com>
Indexed By Thread Previous: UDP 137
From: gary flynn <gary @ habanero . jmu . edu>
Next: Re: Check Point and SYN Flood Attack
From: "Bruce M." <bkmarsh @ feist . com>

Google
 
Search Internet Search www.greatcircle.com