[KLUG Members] strange network things

Bert members@kalamazoolinux.org
Tue, 29 Apr 2003 11:24:55 +0200


Peter Buxton wrote:

>On Mon, Apr 28, 2003 at 04:58:59PM +0200, Bert wrote:
>
>  
>
>>But no network activities is reported by either by 'ethereal' or
>>'ngrep'. I know DCOM uses port 135 to initialize.
>>    
>>
>
>Isn't 135 the portmapper for Windows? In other words, that's not so much
>an init step as it is a port discovery phase.
>
>  
>
Yes it is, but no activities on that port on any moment. I did shutdown 
the 'client', rebooted, and waited for connections on port 135. nop.
But even after port 135 has done its mapping thing, no ip-packets 
between the two systems are seen, although the client updates its data 
nicely.

Since I try for some time no to monitor the ip traffic there must be 
something that I am (or my sniffers are) missing here. Any ideas how to 
grab this?


Bert.