I am finding some traffic on our internal LAN originating from a Win 2k server and attempting to go to a 192.168.x.x address that doesn't exist (we use 172.x.x.x). It originates up in the 40000's and always attempts to go to the same IP on UDP 1451. It is a small packet not plain text (i used Microsoft net mon to catch it quickly). I have checked Iana and they say the port is for IBM Infoman traffic. We don't use any IBM software (or Tivoli which also uses 1451 I believe) and I have checked on NAI (AV software), CAI (Backup) and APC (UPS). We don't use any other software other than the Microsoft stuff. It is not an issue other than it is annoying not knowing what sevice is causing it and stop it. Any ideas or pointers would be handy.
Regards Mat
