• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

network monitoring software

NeoV

Diamond Member
Hey all

I am in charge of the IT department for a small company - I've only got one full-time person dedicated to IT, and I back up all of those functions in addition to being the controller.

While I'm no network teacher, I know a fair amount.

Yesterday and today we've experience a significant downturn in our network performance, and our remote users have had trouble accessing email and VPN connections.

The servers appear to be running just fine.

However, a call to our local company that maintains our T1 line has a guy telling us that we have all kinds of traffic on port 135, and we come up with a list of 13 or 14 internal IP addy's that seem to be the main offenders.

How can I look at traffic in the same way that they were? Are there tools that allow you to troubleshoot this kind of stuff?

thx
 
Virus possible. I've included a link too.

http://www.linklogger.com/TCP135.htm

TCP Port 135
Common Use
Microsoft Remote Procedure Call (RPC) service.

Inbound Scan
Currently inbound scans are likely the Nachi or MSBlast worms.

Outbound Scan
Outbound scans if occurring in volume should be considered an indication of a possible worm infection on the source computer and should be investigated.

I use Ethereal to sniff the network.

http://www.ethereal.com/
 
Back
Top