Hello, We have recently set up an IDS (Intrusion Detection) system on our network and are seeing a large amount of ICMP traffic (pings) traveling from all client workstations to our two Domain Controllers, that are also running DNS. We are a mixed mode domain. I was just wondering if anybody knew if it is normal for a client workstation to contact a domain controller at regular intervals via ping/ICMP or not? Why does this happen/is this something that I should worry about? Thanks, /jL