too much traffic from clients to DC port 389

hi,

today we are observing many sessions from clients to a DC / DNS (all 5 roles on it) on port 389

they have an about 2MB session on this port (like they are getting something from it)

but as the port is 389 i do not have an idea what are these connections

Antivirus is updated on all of them and ... ! no new policy, not any change ..

what can be this traffic ?!?!


March 5th, 2013 10:46am

There are several good methods to review the queries being run on a DC; but my favorite for troubleshooting is the Microsoft Server Performance Advisor.  You'll need the right version for the DCs OS; and you will have to install it on the DC to collect a snapshot of performance. 

2008-2012: http://msdn.microsoft.com/en-us/library/windows/hardware/hh367834.aspx

2003:  http://www.microsoft.com/en-us/download/details.aspx?id=15506

Look for the Active Directory Role.

David Taylor

Former Microsoft PFE

www.theUnluckyFish.com

Free Windows Admin Tool Kit Click here and download it now
March 5th, 2013 8:39pm

There are several good methods to review the queries being run on a DC; but my favorite for troubleshooting is the Microsoft Server Performance Advisor.  You'll need the right version for the DCs OS; and you will have to install it on the DC to collect a snapshot of performance. 

2008-2012: http://msdn.microsoft.com/en-us/library/windows/hardware/hh367834.aspx

2003:  http://www.microsoft.com/en-us/download/details.aspx?id=15506

Look for the Active Directory Role.

David Taylor

Former Microsoft PFE

www.theUnluckyFish.com

Thanks ! I will test it

but is this normal ? maybe it is normal to see a 2000KB traffic from clients to Port 389 of DC ? is that it ? or there is something wrong ?

March 6th, 2013 8:24am

Hi,

You can also use Netmon or Wireshark to trace the network traffic and have a check.

Regards,
Cicely

Free Windows Admin Tool Kit Click here and download it now
March 14th, 2013 4:36am

I made a capture with wireshark just on ldap protocol and a very big file for just about 10 minutes is there

i should look at it to find something interesting

and my question still exists

is it normal on your networks guy ? do u see a 2MB traffic on ldap from clients to servers (domain controllers ? )

March 14th, 2013 8:29am

Hi we are having the same issue, did you ever find a solution or what the problem was?
Free Windows Admin Tool Kit Click here and download it now
August 13th, 2014 5:54am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics