Take a peek at this. Can't be a virus since we're pretty good with this stuff.
---------------------------------------------------
02/14/05 10:02 firewalld[105]: deny out eth1 78 udp 20 128 10.1.1.63 10.1.1.255 137 137 (spoofed source address)
02/14/05 10:02 firewalld[105]: deny out eth1 78 udp 20 128 10.1.1.163 10.1.1.255 137 137 (spoofed source address)
---------------------------------------------------
Lots of IP addresses listed. I read on google that these clients can't find the DHCP server and it resorts to the default broadcast ip address 10.1.1.255. I triple check the DHCP/DNS server which also acts as the Active Directory server. It all seems fine. Could it be a virus?
---------------------------------------------------
02/14/05 10:02 firewalld[105]: deny out eth1 78 udp 20 128 10.1.1.63 10.1.1.255 137 137 (spoofed source address)
02/14/05 10:02 firewalld[105]: deny out eth1 78 udp 20 128 10.1.1.163 10.1.1.255 137 137 (spoofed source address)
---------------------------------------------------
Lots of IP addresses listed. I read on google that these clients can't find the DHCP server and it resorts to the default broadcast ip address 10.1.1.255. I triple check the DHCP/DNS server which also acts as the Active Directory server. It all seems fine. Could it be a virus?