We're now a non-profit! Support open source packet analysis by making a donation.

Wireshark-users: [Wireshark-users] Strange packet nbns

From: "Jon Knight" <JKnight@xxxxxxxxx>
Date: Sun, 18 Feb 2007 20:25:40 +1100

Hi all


Hope you can help.  I tried Wireshark on my network and once a winxp client logs into my network (Win 2003 server as DC) I see NBNS name query nb bps-ntserver1

The bps-ntserver1 was an old NT 4 server but I have since built a new domain.  I have a feeling a reg key or something is still in the desktop since the change over.  I have looked through the registry but it is strange why its being called on login only?  Any ideas? I am guessing it is not healthy for 100+ pc’s querying an old server on login! I have attached the log. 


I am still (unfortunately) running wins on the network due to a few win 98 boxes still running.  I have tried searching wins for that server name but nothing exists and DNS does not have any reference to that old server name.  Thanks.




Attachment: nbns.pcap
Description: Binary data