Hello,
I was hoping someone could give me more information on the following Alert our Cisco Firewalls keep generating regarding our Meraki AP.
We keep getting spammed alerts regarding SMB - Bad NetBIOS Session Service session type From "FTDHA-1" [Classification: Potentially Bad Traffic] [Priority: 2] {tcp} 64.95.103.190:445 (united states)->(Our Meraki Access Point):51251 (unknown)'
We believe this device is connected to our guest network and because our AP is set for NAT its being forwarded to our firewalls. I am not able to locate this device on our Meraki AP and was wondering if anyone had any ideas on how to track this device down?
Any additional information would be greatly appreciated.