T
2018-04-06 23:25:26 UTC
Hi All,
How do I chase down who is doing a multicast (224.0.0.252) on
my local network.
My Windows Security log is gobsmacked with the following:
Network Information:
Direction: Inbound
Source Address: 224.0.0.252
Source Port: 5355
Destination Address: 192.168.202.215
Destination Port: 52860
Protocol: 17
This gets me no where:
# nmap -A -T4 -Pn 224.0.0.252
Starting Nmap 7.60 ( https://nmap.org ) at 2018-04-06 16:22 PDT
Nmap done: 1 IP address (0 hosts up) scanned in 0.85 seconds
My firewall shows no traffic outbound to 224.0.0.252
Many thanks,
-T
How do I chase down who is doing a multicast (224.0.0.252) on
my local network.
My Windows Security log is gobsmacked with the following:
Network Information:
Direction: Inbound
Source Address: 224.0.0.252
Source Port: 5355
Destination Address: 192.168.202.215
Destination Port: 52860
Protocol: 17
This gets me no where:
# nmap -A -T4 -Pn 224.0.0.252
Starting Nmap 7.60 ( https://nmap.org ) at 2018-04-06 16:22 PDT
Nmap done: 1 IP address (0 hosts up) scanned in 0.85 seconds
My firewall shows no traffic outbound to 224.0.0.252
Many thanks,
-T