Hi All, we have windows 2003 server R2 enterprise edition DC (IP address 10.71.2.24), Microsoft cluster service (Oracle database) active/passive two node cluster (heartbeat IP address 192.168.1.6 and .5 ) and SAN Dell iSCSI (IP address 192.168.110.4 and 192.168.110.5). For past few weeks we have observed that in the firewall those IP addresses ( heartbeat and iSCSI) are hit by our DC (10.71.2.24) and at random port like 137, 22745 etc. Not able to find out which services of DC try to hit those IP address.
↧