This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Unexplained Network Traffic to Parent Router

Hi

I have a 2012R2 Server with Sophos Enterprise Console 5.2.1R2 installed.

The server has two NICs, one on the 'default VLAN' and one on a 'SAN VLAN'.

On the server...

I have removed the 'SAN VLAN' IP address/interface from the MRINIT.CONF file.

In the registry I have also modified the -ORBListenEndpoints for the RMS and Server Agent so that only the 'default VLAN' IP address is used.

On the client(s), In the Remote Management logs I can see the IOR being received from the server, and using an online checker I have been able to see that the IOR contains only the 'default VLAN' address (<default VLAN IP Address:8193>

So all looks ok.

But, our network is being flooded with TCP traffic from all the clients trying to send data to the 'SAN VLAN' on port 8194.

How can this be? The IOR doesn't include that address, so how could the clients possibly know about it? On the clients I can't find any reference to the 'SAN VLAN' address in the registry and the MRINIT.CONF file is correct.

I'm really confused. Please help.

Thanks

Andrew

:46501


This thread was automatically locked due to age.
Parents
  • On a typical client that the firewall identifies as sending to traffic to 10.113.0.4, looking at the logs here:

    c:\ProgramData\Sophos\Remote Management System\3\Router\Logs

    I have the entry:

    Received parent router's IOR:

    IOR: <string of numbers>

    Using the IOR parser (http://www2.parc.com/istl/projects/ILU/parseIOR/), the IOR string contains a link to 172.21.1.22:8193, NOT to 10.113.0.4.

    The above is working as I understand it to, so it's strange the firewall is seeing this traffic.

    I'll try and take a look at verbose logging to see I can see what's happening here...

    :46511
Reply
  • On a typical client that the firewall identifies as sending to traffic to 10.113.0.4, looking at the logs here:

    c:\ProgramData\Sophos\Remote Management System\3\Router\Logs

    I have the entry:

    Received parent router's IOR:

    IOR: <string of numbers>

    Using the IOR parser (http://www2.parc.com/istl/projects/ILU/parseIOR/), the IOR string contains a link to 172.21.1.22:8193, NOT to 10.113.0.4.

    The above is working as I understand it to, so it's strange the firewall is seeing this traffic.

    I'll try and take a look at verbose logging to see I can see what's happening here...

    :46511
Children
No Data