Can anyone explain this?
TIA
duhjosh~~at~~hotmail~~dot~~c~o~m
Well I finally figured out what this was. I hope the anonymous poster
who had this same problem back in November was able to figure out what
was going on quickly and didn't spend too much time on this. I'll
post the details here in case this weird behavior is noticed by
someone else. Maybe it will save a day of troubleshooting and
tracking... :)
It turned out to be an HP printer on my network that wasn't DHCP'ing
all of a sudden and registered itself as 85.85.170.170. I used MS's
network monitor to watch one of my servers that was sending data out
to IP 85.85.170.170 port 1230 and grabbed the MAC address of the box.
Looking up the MAC vendor code online I determined that it was an HP
NIC. The only HP NICs I have on my network are printers. After
finally finding the MAC in my DHCP system and turning off the
suspected printer, the requests stopped. Something had happened to
this stupid printer where all of a sudden it wasn't able to DHCP, it
registered itself as 85.85.170.170 and started broadcasting NTP
requests to port 123 on subnet 255.255.255.255. We reset the printer
back to factory defaults and everything was fine after that. Oh well,
another day wasted tracking down weird network behavior. Hopefully
the next time someone sees this behavior and Google's it they will
come across this solution. :D