Friday, July 6, 2018

AnyConnect Clients Spamming NetBios

Im having an issue where Anyconnect VPN users are slamming netbios. In my wireshark trace I’m seeing VPN users 10.18.254.X hitting 10.18.254.255. Its generating so much traffic on the ASA that its CPU is hitting 80% with only 12 users connected. We just upgraded from a ASA5010 to a ASA5508 with the current IOS as well. The old ASA has version 7.X I think.

I noticed one fix is to use a detected DHCP Server and removed option 43 and move away from the ASA anyconnect pool all together.

Has anyone else seen this? Im at a complete loss as to why im seeing his now compared to before.

Thanks for the help all. Happy Friday :/



No comments:

Post a Comment