CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Topology Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-02-22
Junior Member
 
Join Date: 2006-09-26
Posts: 18
Rep Power: 0
jchrisos has an average reputation (10+)
Default Management station attempting external nbname connections?!?!

I am seeing dropped traffic from my Windows management station to a ton of external IPs on UDP port 137 from UDP 137. I scanned the machine (Win2k3 standard) with an updated virus scanner and it found no malware. Anyone else ever experience this?? Maybe this means I need to move to SPLAT ;-)
Reply With Quote
  #2 (permalink)  
Old 2007-02-22
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Management station attempting external nbname connections?!?!

TCP/UDP 137 is netbios name service.
What do you mean "Windows management station"? SmartCenter or your computer with SmartConsole?

I think you can disable NetBios service on Check Point servers. It's more secure.
Reply With Quote
  #3 (permalink)  
Old 2007-02-22
Junior Member
 
Join Date: 2006-09-26
Posts: 18
Rep Power: 0
jchrisos has an average reputation (10+)
Default Re: Management station attempting external nbname connections?!?!

Quote:
Originally Posted by kva.kva View Post
TCP/UDP 137 is netbios name service.
What do you mean "Windows management station"? SmartCenter or your computer with SmartConsole?

I think you can disable NetBios service on Check Point servers. It's more secure.
Sorry - the management console is Windows, which is also where logs are sent. SmartCenter is installed there as well as locally on my PC.

Under normal circumstances, a windows machine shouldn't be trying to contact the outside world on windows ports unless it's infected with something. I wanted to know if what I am seeing is common for a management console or do I possibly have malware that my AV scanner isn't picking up.

Jim
Reply With Quote
  #4 (permalink)  
Old 2007-08-20
Junior Member
 
Join Date: 2007-08-08
Posts: 24
Rep Power: 0
drhex2000 has an average reputation (10+)
Default Re: Management station attempting external nbname connections?!?!

Hi all,

was this ever resolved? Have the same problem here with UTM R65.

Thanks,

Florian
Reply With Quote
  #5 (permalink)  
Old 2007-08-22
Junior Member
 
Join Date: 2006-09-26
Posts: 18
Rep Power: 0
jchrisos has an average reputation (10+)
Default Re: Management station attempting external nbname connections?!?!

Quote:
Originally Posted by drhex2000 View Post
Hi all,

was this ever resolved? Have the same problem here with UTM R65.

Thanks,

Florian
Unfortunately I have not resolved this. I am trusting that what I am seeing is supposed to happen. If anyone can shed any light on this, I'm all ears!
Reply With Quote
  #6 (permalink)  
Old 2007-08-26
Junior Member
 
Join Date: 2005-11-08
Posts: 8
Rep Power: 0
khanta has an average reputation (10+)
Default Re: Management station attempting external nbname connections?!?!

I had this same issue about 1.5 years ago on an R55 box. The machine would try and send netbios datagrams. I never got a resolution to it. I did notice that basically the management station (with smart tracker) would try and send nb datagrams to ips that it was doing a reverse lookup on.

Hope that helps.

Had another issue that was similar that was not checkpoint related, I had a windows box that would send out 137 and 139 datagrams to various servers on the internet. It was a windows thing. Tried every antimalware and rootkit and antivirus scanner out there, never found anything. There were a few other people that had the same issue. Google loki74@gmail.com and you will see my post out there.

Good luck.
Reply With Quote
  #7 (permalink)  
Old 2007-08-27
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Management station attempting external nbname connections?!?!

These are not Check Point issues. Windows will try NBT connections to lots of things on the Internet. This is one of the many reasons not to use Windows as your SmartCenter.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:25.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0