Hi All,
We recently had major network slowdowns on our network.
While trying to find the cause I started using WireShark to analyse the traffic.
I found that our workstations are Querying old servers that in some cases were on the old domain?
in wireshark I get repeatadly when a user logs in:
SOURCE-IP TRAGET-IP NBNS Name Query NB HUMPHREY<20>
HUMPHREY was our old PDC before the network was rebuilt a few years back, and CMIS-NEW was the new facility server that was only names CMIS-NEW for a few days until the old CMIS server was decomissioned?
One of our servers also used to be called CMIS-NEW before it was renamed to FACILITY.
I am now getting from that server:
SOURCE-IP: FACILITY TRAGET-IP NBNS Name Query NB CMIS-NEW<20>
Also workstations randomly cause:
SOURCE-IP TRAGET-IP NBNS Name Query NB WPAD<00>
I original thought it was a script referencing the old servers but I cant find anything anywhere.
Nothing in GP also as ive moved it into the Computers OU where no GPs are called.
Theres also nothing in DNS
Can anyone please shed any light?
PS. domain admin does not cause these references.


LinkBack URL
About LinkBacks




