About this question
In our local domain environment, we use Sophos UTM to protect our network. When I check the firewall logs, I can see that a huge number of packets dropped by the firewall are netbios-ns (UDP 137) broadcasts. Checking for more details reveals that these blocked packets were all generated by one of the DCs. My questions are:
How to deal with this? Why are they all generated by only one of our DNS servers and not the other two (we have 3 DNS servers)? I would really like to know if it is safe to disable NetBIOS as DNS is supposed to serve the purpose.