Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Ref: Netlogon SAM Logon (ICMP)

Status
Not open for further replies.

egulbran

MIS
Jun 8, 1999
3
US
Dear committee members :),
I have a strange trace file, and can't seem to find any info on it....go figure....
All of the client nodes on boot up send out a DNS request, this process works fine...
After the IP address resolves the client broadcasts a WINS query for the specified domain.
One of the domain controllers responds.
The frame has a Flags = 85
Response = 1
Then an answer section
Name = Domain<1c> <Domain Controller>
Type = NETBIOS name service (WINS) (Netbios name, 32)

Then it lists other Group NetBios name..
Node address = 1.1.1.1 dns.name.com

Question is where is the Group Netbios name info coming from? There are a couple of bad addresses in this fram, and the client then tries to contact a bogus node which generates ICMP unreachables.....I would like to know where to clear out the bad addresses from, I checked Wins and Domain Controllers and doesn't seem to be easily located there....big surprise right......

Thanx in advance.....
 
Hi egulbran,

The group NetBIOS names come from the <1C> WINS record. If you open your WINS Manager and search for your DOMAIN NAME, you will see a list of records with different types (e.g. 00h, 1Ch, 1Eh, etc.) Double-click on the <1C> record to see the IP addresses of domain controllers. When the client receives this list, it will try to logon to one of these servers.

To remove unwanted IP addresses from the <1C> record, refer to this Microsoft Knowledgebase document:


J.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top