Why is Mikrotik router using DRDA protocol?
Hello, I am seeing a lot of traffic on protocol DRDA between my router (10.10.10.1) and laptop (10.10.10.254)
Any idea what this is? I have searched and cannot find much, all I found is linked at the bottom
I am using a Mikrotik hEX RB750Gr3 running router OS version 6.49.10 (stable)
The other day I also noticed TDS / TDS5 packets going between the router and laptop (but very few, like 1 or 2 at a time very infrequently)
Link1: https://thenetworkguy.typepad.com/nau... Here you'll see the Info column usually has info, all of mine are Unknown
Link2: https://gitlab.com/wireshark/wireshar... Here again something other than Unknown in the info column.
See screenshot here: https://ibb.co/vxZmj6C
UPDATE: Thanks to Chuckc for the helpful posts, I disabled DRDA in the list of enabled protocols and now Wireshark decodes the packets as TCP so it looks like it was a case of it incorrectly seeing this packets as DRDA
Wireshark is a packet analyser. It can attempt to tell you what is in the packets but not why they are sent.
Please update question with output of
wireshark -v
orHelp -> About Wireshark:Wireshark
.The Wireshark Wiki Sample Captures has a
DRDA
capture: