BooBoo Posted June 16, 2009 Posted June 16, 2009 Hi Folks, I have a Windows Server 2008 box that on Wednesday starting firing out LLMNR packets on port 5355. At it's peak it was firing 29,000 a second. Which crippled our network and some of the sourounding schools lost the internet. I have disable IPv6 on the NIC and have used group policy and a registry hack to disable LLMNR traffic but I still have the storm occuring. NOD 32 show nothing and Search and Destroy comes back clean. I don't want to rebuild this server as it it one of our application servers. I could use a backup but I'm afraid that without knowing the cause or cure it might occur again. Any ideas?
SYNACK Posted June 16, 2009 Posted June 16, 2009 (edited) Could try switching it off for now - as it is of limited use on an established lan: (Vista but reg should be the same or at least GP) How to disable LLMNR - microsoft.public.windows.vista.networking_sharing | Google Groups Microsoft Enterprise Networking Team : How to benefit from Link-Local Multicast Name Resolution. Edited June 16, 2009 by SYNACK
BooBoo Posted June 23, 2009 Author Posted June 23, 2009 I've already tried both of those but to no avail. It now looks like with the exception of my Exchange server all of my Win 2008 and Vista machines broadcast on the network immediatley. My next step will be to 'pull' buildings off the network to see if a machine in an adjacent building is telling these machines to broadcast. SpyBot S&D and NOD32 both come back negative. Any other ideas? Martin
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now