mstewarth2opolo
IS-IT--Management
I work for a company that supports high speed internet in hotels, and we see traffic being generated on our network that is being sent to the DHCP IP address, and using TCP port 7, and TCP port 80. I have attached a screen shot of the traffic. IP 172.27.172.24 is the IP for the Guest, and IP 172.27.172.2 is the IP of our DHCP server. Does anyone know what this traffic is?
(106) 172.27.172.24/3110 <-> 12.170.115.66/5034 ---> 172.27.172.2/7 TCP MAPPED to=193
(107) 172.27.172.24/3111 <-> 12.170.115.66/5039 ---> 172.27.172.2/80 TCP MAPPED to=193
(108) 172.27.172.24/3113 <-> 12.170.115.66/5040 ---> 172.27.172.2/7 TCP MAPPED to=173
(109) 172.27.172.24/3114 <-> 12.170.115.66/5041 ---> 172.27.172.2/80 TCP MAPPED to=173
(110) 172.27.172.24/3116 <-> 12.170.115.66/5042 ---> 172.27.172.2/7 TCP MAPPED to=153
(111) 172.27.172.24/3117 <-> 12.170.115.66/5043 ---> 172.27.172.2/80 TCP MAPPED to=153
(112) 172.27.172.24/3118 <-> 12.170.115.66/5069 ---> 172.27.172.2/7 TCP MAPPED to=133
(113) 172.27.172.24/3119 <-> 12.170.115.66/5111 ---> 172.27.172.2/80 TCP MAPPED to=133
(114) 172.27.172.24/3121 <-> 12.170.115.66/5112 ---> 172.27.172.2/7 TCP MAPPED to=113
(115) 172.27.172.24/3122 <-> 12.170.115.66/5113 ---> 172.27.172.2/80 TCP MAPPED to=113
(116) 172.27.172.24/3124 <-> 12.170.115.66/5044 ---> 172.27.172.2/7 TCP MAPPED to=93
(117) 172.27.172.24/3125 <-> 12.170.115.66/5045 ---> 172.27.172.2/80 TCP MAPPED to=93
(118) 172.27.172.24/3126 <-> 12.170.115.66/5048 ---> 172.27.172.2/7 TCP MAPPED to=73
(119) 172.27.172.24/3127 <-> 12.170.115.66/5049 ---> 172.27.172.2/80 TCP MAPPED to=73
(120) 172.27.172.24/3129 <-> 12.170.115.66/5050 ---> 172.27.172.2/7 TCP MAPPED to=53
(121) 172.27.172.24/3130 <-> 12.170.115.66/5051 ---> 172.27.172.2/80 TCP MAPPED to=53
(122) 172.27.172.24/3132 <-> 12.170.115.66/5070 ---> 172.27.172.2/7 TCP MAPPED to=33
(123) 172.27.172.24/3133 <-> 12.170.115.66/5072 ---> 172.27.172.2/80 TCP MAPPED to=33
(124) 172.27.172.24/3134 <-> 12.170.115.66/5073 ---> 172.27.172.2/7 TCP MAPPED to=13
(125) 172.27.172.24/3135 <-> 12.170.115.66/5074 ---> 172.27.172.2/80 TCP MAPPED to=13
(106) 172.27.172.24/3110 <-> 12.170.115.66/5034 ---> 172.27.172.2/7 TCP MAPPED to=193
(107) 172.27.172.24/3111 <-> 12.170.115.66/5039 ---> 172.27.172.2/80 TCP MAPPED to=193
(108) 172.27.172.24/3113 <-> 12.170.115.66/5040 ---> 172.27.172.2/7 TCP MAPPED to=173
(109) 172.27.172.24/3114 <-> 12.170.115.66/5041 ---> 172.27.172.2/80 TCP MAPPED to=173
(110) 172.27.172.24/3116 <-> 12.170.115.66/5042 ---> 172.27.172.2/7 TCP MAPPED to=153
(111) 172.27.172.24/3117 <-> 12.170.115.66/5043 ---> 172.27.172.2/80 TCP MAPPED to=153
(112) 172.27.172.24/3118 <-> 12.170.115.66/5069 ---> 172.27.172.2/7 TCP MAPPED to=133
(113) 172.27.172.24/3119 <-> 12.170.115.66/5111 ---> 172.27.172.2/80 TCP MAPPED to=133
(114) 172.27.172.24/3121 <-> 12.170.115.66/5112 ---> 172.27.172.2/7 TCP MAPPED to=113
(115) 172.27.172.24/3122 <-> 12.170.115.66/5113 ---> 172.27.172.2/80 TCP MAPPED to=113
(116) 172.27.172.24/3124 <-> 12.170.115.66/5044 ---> 172.27.172.2/7 TCP MAPPED to=93
(117) 172.27.172.24/3125 <-> 12.170.115.66/5045 ---> 172.27.172.2/80 TCP MAPPED to=93
(118) 172.27.172.24/3126 <-> 12.170.115.66/5048 ---> 172.27.172.2/7 TCP MAPPED to=73
(119) 172.27.172.24/3127 <-> 12.170.115.66/5049 ---> 172.27.172.2/80 TCP MAPPED to=73
(120) 172.27.172.24/3129 <-> 12.170.115.66/5050 ---> 172.27.172.2/7 TCP MAPPED to=53
(121) 172.27.172.24/3130 <-> 12.170.115.66/5051 ---> 172.27.172.2/80 TCP MAPPED to=53
(122) 172.27.172.24/3132 <-> 12.170.115.66/5070 ---> 172.27.172.2/7 TCP MAPPED to=33
(123) 172.27.172.24/3133 <-> 12.170.115.66/5072 ---> 172.27.172.2/80 TCP MAPPED to=33
(124) 172.27.172.24/3134 <-> 12.170.115.66/5073 ---> 172.27.172.2/7 TCP MAPPED to=13
(125) 172.27.172.24/3135 <-> 12.170.115.66/5074 ---> 172.27.172.2/80 TCP MAPPED to=13