Karnaugh
Banned
On the 28th of November I noticed the security log files on azrael rotating at an alarming rate. When I viewed the security logs I noticed large amounts of multicast data being blocked. This surprised me as it was coming from my own RAS, ndn-ip-nas-1.telkom-ipnet.co.za.
Nov 28 12:53:11 azrael kernel: ipfw: 33910 Deny P:2 155.239.193.254 224.0.0.1 in via tun0
Nov 28 12:53:29 azrael kernel: ipfw: 33910 Deny P:103 155.239.193.254 224.0.0.13 in via tun0
Nov 28 12:53:59 azrael kernel: ipfw: 33910 Deny P:103 155.239.193.254 224.0.0.13 in via tun0
Closer inspection of the packets revealed they were IGMP router multicasts.
<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote">18:45:06.323780 155.239.193.254 > 224.0.0.1: igmp query v2 [tos 0xc0] [ttl 1]
0x0000 45c0 001c bccd 0000 0102 be63 9bef c1fe E..........c....
0x0010 e000 0001 1164 ee9b 0000 0000 .....d......
18:45:22.343766 155.239.193.254 > 224.0.0.13: pim v2 Hello (Hold-time 1m45s) (Genid: 0x000006c0) (bidir-capable) (DR-Priority: 1) (State Refresh Capable; v1) [tos 0xc0] [ttl 1]
0x0000 45c0 003a c933 0000 0167 b16e 9bef c1fe E..:.3...g.n....
0x0010 e000 000d 2000 d774 0001 0002 0069 0014 .......t.....i..
0x0020 0004 0000 06c0 0016 0000 0013 0004 0000 ................
0x0030 0001 0015 0004 0100 0000 .......... <hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">
I checked this information with various other people who said they had had this for a long time. This surprised me for a few reasons.
1) I was receiving it at a rate of 3 to 4 packets every minute (Resulting in noticeable decreases in throughput on analysis with trafshow). Most people's logs only showed 1 packet every minute at most.
2) This had to have been a new policy (or mistake) because I have had the same set of firewall logs for over 6 months and I'm very sure I would have noticed that level of log activity.
I had dropped just over 12000 packets that day, when I decided to contact SAIX to find the reason for this.
SAIX replied that this was "just normal Multicast".
This leaves me with some unanswered questions. For what purpose are SAIX broadcasting IGMP to their dialup and ADSL users?
From what I know, this should *never* happen and is recent. It also coincidently coincides with peoples complaints about spiky latency.
<hr noshade size="1">iActive internet services
http://www.iactive.co.za
Nov 28 12:53:11 azrael kernel: ipfw: 33910 Deny P:2 155.239.193.254 224.0.0.1 in via tun0
Nov 28 12:53:29 azrael kernel: ipfw: 33910 Deny P:103 155.239.193.254 224.0.0.13 in via tun0
Nov 28 12:53:59 azrael kernel: ipfw: 33910 Deny P:103 155.239.193.254 224.0.0.13 in via tun0
Closer inspection of the packets revealed they were IGMP router multicasts.
<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote">18:45:06.323780 155.239.193.254 > 224.0.0.1: igmp query v2 [tos 0xc0] [ttl 1]
0x0000 45c0 001c bccd 0000 0102 be63 9bef c1fe E..........c....
0x0010 e000 0001 1164 ee9b 0000 0000 .....d......
18:45:22.343766 155.239.193.254 > 224.0.0.13: pim v2 Hello (Hold-time 1m45s) (Genid: 0x000006c0) (bidir-capable) (DR-Priority: 1) (State Refresh Capable; v1) [tos 0xc0] [ttl 1]
0x0000 45c0 003a c933 0000 0167 b16e 9bef c1fe E..:.3...g.n....
0x0010 e000 000d 2000 d774 0001 0002 0069 0014 .......t.....i..
0x0020 0004 0000 06c0 0016 0000 0013 0004 0000 ................
0x0030 0001 0015 0004 0100 0000 .......... <hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">
I checked this information with various other people who said they had had this for a long time. This surprised me for a few reasons.
1) I was receiving it at a rate of 3 to 4 packets every minute (Resulting in noticeable decreases in throughput on analysis with trafshow). Most people's logs only showed 1 packet every minute at most.
2) This had to have been a new policy (or mistake) because I have had the same set of firewall logs for over 6 months and I'm very sure I would have noticed that level of log activity.
I had dropped just over 12000 packets that day, when I decided to contact SAIX to find the reason for this.
SAIX replied that this was "just normal Multicast".
This leaves me with some unanswered questions. For what purpose are SAIX broadcasting IGMP to their dialup and ADSL users?
From what I know, this should *never* happen and is recent. It also coincidently coincides with peoples complaints about spiky latency.
<hr noshade size="1">iActive internet services
http://www.iactive.co.za