Ok needed the name of the adapter got it take a look at the output
The first one was port 5544 this is strange that the computer tgkw005 is the only one this is a VM XP computer I run and I have not installed NXLOG service on this machine
The second one was port 3515 you see TGCS013 that is a Windows 2012 Server that I installed NXLOG service on again why is TGKW005 showing?
Also do not see my Meraki 10.2.8.1 or my switch 10.2.8.6
eno16777984: flags=4163<UP,BROADCAST,RUNNING,MULTICAST> mtu 1500
inet 10.2.8.74 netmask 255.255.252.0 broadcast 10.2.11.255
inet6 fe80::20c

fe8a:554e prefixlen 64 scopeid 0x20<link>
ether 00:0c:29:8a:55:4e txqueuelen 1000 (Ethernet)
RX packets 5030262 bytes 6345009212 (5.9 GiB)
RX errors 0 dropped 183 overruns 0 frame 0
TX packets 3126909 bytes 480222302 (457.9 MiB)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
lo: flags=73<UP,LOOPBACK,RUNNING> mtu 65536
inet 127.0.0.1 netmask 255.0.0.0
inet6 ::1 prefixlen 128 scopeid 0x10<host>
loop txqueuelen 0 (Local Loopback)
RX packets 11149539 bytes 2555311829 (2.3 GiB)
RX errors 0 dropped 0 overruns 0 frame 0
TX packets 11149539 bytes 2555311829 (2.3 GiB)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
Code: Select all
[root@TGCS018 ~]# tcpdump port 5544 -i eno16777984
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eno16777984, link-type EN10MB (Ethernet), capture size 65535 bytes
16:57:05.605131 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 243
16:57:07.074202 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 152
16:57:22.002493 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 167
16:57:22.015254 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 165
16:57:45.241904 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 156
16:57:52.125338 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 220
16:57:52.281057 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 224
16:57:52.336398 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 235
16:57:52.401055 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 218
16:57:52.450886 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 203
16:57:52.498124 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 225
16:57:52.553333 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 221
16:57:52.600982 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 215
16:57:52.652796 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 208
16:57:52.700321 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 221
16:57:52.748229 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 219
16:57:52.790939 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 231
16:58:04.531920 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 151
16:58:48.784318 IP 10.2.8.6.personal-agent > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 154
16:58:55.029974 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 150
16:59:07.099059 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 151
16:59:14.914511 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 151
16:59:45.242038 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 158
16:59:46.920977 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 157
16:59:47.371226 IP 10.2.8.6.personal-agent > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 157
16:59:47.523571 IP 10.2.8.6.personal-agent > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 154
16:59:47.532615 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 153
16:59:47.990114 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 168
16:59:48.820703 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 154
16:59:51.466731 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 243
16:59:54.339935 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 169
17:00:13.811160 IP 10.2.8.6.personal-agent > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 138
17:00:13.811467 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 153
17:00:15.417925 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 185
17:00:17.005933 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 154
17:00:17.193594 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 162
17:00:18.017552 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 167
17:00:18.460456 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 165
17:00:27.515591 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 167
17:00:33.213538 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 162
17:00:42.160691 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 154
17:00:42.365449 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 162
17:00:43.201444 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 167
17:00:43.634108 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 165
17:00:44.953937 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 221
17:00:45.132115 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 221
17:00:45.176214 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 219
17:00:45.225217 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 219
17:00:55.364055 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 153
17:01:07.124181 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 151
17:01:07.124257 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 151
17:01:07.125929 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 151
17:01:07.174043 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 151
17:01:07.175380 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 151
17:01:10.335103 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 151
17:01:29.112309 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 149
17:01:30.540238 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 151
17:01:33.665841 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 162
17:01:54.175914 IP 10.2.8.1.49069 > tgkw005.myvm.our.network.tgcsnet.com.5544: UDP, length 165
^C
59 packets captured
59 packets received by filter
0 packets dropped by kernel
[root@TGCS018 ~]# tcpdump port 3515 -i eno16777984
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eno16777984, link-type EN10MB (Ethernet), capture size 65535 bytes
17:02:39.960208 IP tgcs013.our.network.tgcsnet.com.51940 > tgkw005.myvm.our.network.tgcsnet.com.must-backplane: Flags [SEW], seq 2496432202, win 8192, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
17:02:39.960261 IP tgkw005.myvm.our.network.tgcsnet.com.must-backplane > tgcs013.our.network.tgcsnet.com.51940: Flags [R.], seq 0, ack 2496432203, win 0, length 0
17:02:40.475150 IP tgcs013.our.network.tgcsnet.com.51940 > tgkw005.myvm.our.network.tgcsnet.com.must-backplane: Flags [S], seq 2496432202, win 8192, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
17:02:40.475216 IP tgkw005.myvm.our.network.tgcsnet.com.must-backplane > tgcs013.our.network.tgcsnet.com.51940: Flags [R.], seq 0, ack 1, win 0, length 0
17:02:40.975177 IP tgcs013.our.network.tgcsnet.com.51940 > tgkw005.myvm.our.network.tgcsnet.com.must-backplane: Flags [S], seq 2496432202, win 8192, options [mss 1460,nop,nop,sackOK], length 0
17:02:40.975252 IP tgkw005.myvm.our.network.tgcsnet.com.must-backplane > tgcs013.our.network.tgcsnet.com.51940: Flags [R.], seq 0, ack 1, win 0, length 0
17:04:00.894897 IP tgcs013.our.network.tgcsnet.com.51980 > tgkw005.myvm.our.network.tgcsnet.com.must-backplane: Flags [SEW], seq 3147142332, win 8192, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
17:04:00.894947 IP tgkw005.myvm.our.network.tgcsnet.com.must-backplane > tgcs013.our.network.tgcsnet.com.51980: Flags [R.], seq 0, ack 3147142333, win 0, length 0
17:04:01.393993 IP tgcs013.our.network.tgcsnet.com.51980 > tgkw005.myvm.our.network.tgcsnet.com.must-backplane: Flags [S], seq 3147142332, win 8192, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
17:04:01.394052 IP tgkw005.myvm.our.network.tgcsnet.com.must-backplane > tgcs013.our.network.tgcsnet.com.51980: Flags [R.], seq 0, ack 1, win 0, length 0
17:04:01.894022 IP tgcs013.our.network.tgcsnet.com.51980 > tgkw005.myvm.our.network.tgcsnet.com.must-backplane: Flags [S], seq 3147142332, win 8192, options [mss 1460,nop,nop,sackOK], length 0
17:04:01.894086 IP tgkw005.myvm.our.network.tgcsnet.com.must-backplane > tgcs013.our.network.tgcsnet.com.51980: Flags [R.], seq 0, ack 1, win 0, length 0
^C
12 packets captured
12 packets received by filter
0 packets dropped by kernel
[root@TGCS018 ~]#
Thoughts.
Tom