Just wanted to say thanks. I ran a diagnostic and started looking through the logs. I found multiple entries in the Network Sonar Discovery logs for the IPs I mentioned. Many were in context to discovery scans of the VMs. I then disabled the discovery scan for a night and the entries did not show up, so that confirmed it a bit more. I then started looking into our VM environment and found that there was an old VM for a file server cluster that is no longer used and is scheduled to be decommissioned in the next couple weeks. The VM was using those IP addresses as its internal addresses as you mentioned.
↧