Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Tracking software communication. 1

Status
Not open for further replies.

Chopsy666

Technical User
Mar 11, 2005
59
GB
Hi we have machines that have some software on them, when you insert a card into the card reader, the system authenticates on a remote server, and visits serveral other servers during initialisation (this can be seen because it is launched in different Internet Explorer Windows)

The problem is, i am convinced we are having DNS issues accross the domain, which is showing inconsistent behaviour, so i have changed the host file to reflect the adresses in the I.E windows and this has made them show properly instead of the page cannot be displayed message. however the users still cannot log on, as when they insert their smart card, it just pops up saying cannot access/find server. As this is not an internet window i can not see what address/fqdn it is trying to access hence i can not enter information in the host files.

as i said there are machies that work fully, what can i do on these working Windows XP machines (AD 2003) to monitor what they are talking to and follow the path back to its destination wherever it may be. that way i can get the IP address and hopefully the fqdn.
 
Thanks for that Serbtastic. I was just wondering if there is anything out of the box, nbtstat, arp commands, anything specific that can help me. I will have a look at the product anyway.

Thanks
 
Definatly you will get your answers from Ethereal.

But i strongly suggest you try to find the problem with your DNS instead of using hosts files. If the problem grows and you have many machines, you will end up updating hosts files all day long.
 
@Chopsy,

The quick run is to use the Command Promt and enter "netstat".
The longer run is to install Ethereal, but if you are more convienient with a Windows GUI try packetyzer.
(
 
Hi guys,

thanks for all your help. I tried netstat but it only showed limited info. I downloaded Eathereal and its such a great tool, it gives so much info (or easily read info).
The DNS issue does need resolving, but now im beginning to wonder if we have 2 issues.

When i put the Smart card into a working machine and examine the logs. there are a few packets sent with the machine as the source, and i can see the system handshaking etc with an external ip, and also there are several other entries.

Although i did not spend as much time capturing packets on the bad machine (i stopped as soon as the software wouldnt authenticate) its only had 2 entries of packets originating from it and they were:

Destination Protocol Info
228.7.6.7 IGMP V2 Membership Report
224.0.0.2 IGMP V2 Leave Group

I am only just learning about networking, so i am finding it difficult to fully solve this problem and do not understand why there was not much more activity, The machine it self, can browse the internet, access email etc, just fine.

so any advice would as always be welcome and appreciated

best regards

 
please ignoe he above guys, it was one of our 2 DNS servers. I have now resorted to the good server until i can fix the corrupt one.

thanks again for all your help
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top