Networking Forums

Networking Forums > Network Hardware > Broadband Hardware > SYN Flood: MN-700 Shuts Down Management Tool

Reply
Thread Tools Display Modes

SYN Flood: MN-700 Shuts Down Management Tool

 
 
Steven E. Woolard
Guest
Posts: n/a

 
      02-11-2004, 02:58 AM
I do testing on my LAN for syn flooding to test one of the other PC's
firewalls --- I know the MN-700 has adequate firewall protection ... But
it's for peace of mind.
Anyway... I do this, Spoof the IP, etc, and it freezes the base station's
management tool? LOL ... I can ping it, ping past it, ping my other
computers, and ping web sites .... Everything works but the management tool
.... I don't get it. Why would the management tool even be involved?


 
Reply With Quote
 
 
 
 
Raf
Guest
Posts: n/a

 
      02-11-2004, 05:48 AM
Hey,

Interesting you point this out, because I've seen it
before. May want to try without the BS firewall enabled,
and check the BS log for a IP Spoofing messages.
My theory here is that the BS is rejecting the spoofed IP
on the internal LAN. The 'whois' or broadcast of the
rejection packets back and forth may cause the BS to
lock, or the BSMT. (most likely the BS, fixed by a reset).


Raf
MS fAN



>-----Original Message-----
>I do testing on my LAN for syn flooding to test one of

the other PC's
>firewalls --- I know the MN-700 has adequate firewall

protection ... But
>it's for peace of mind.
>Anyway... I do this, Spoof the IP, etc, and it freezes

the base station's
>management tool? LOL ... I can ping it, ping past it,

ping my other
>computers, and ping web sites .... Everything works but

the management tool
>.... I don't get it. Why would the management tool even

be involved?
>
>
>.
>

 
Reply With Quote
 
Steven E. Woolard
Guest
Posts: n/a

 
      02-11-2004, 07:09 AM
My thoughts were the firewall was flooded by the requests and therefore took
all available processing power (hence the lack of management tool) to lookup
the spoofed IP of the packet ... Or something along those lines. Problem is,
I cannot disable the firewall in the MN-700 --- Which really sucks.


"Raf" <(E-Mail Removed)> wrote in message
news:e30601c3f06b$0feaaa30$(E-Mail Removed)...
> Hey,
>
> Interesting you point this out, because I've seen it
> before. May want to try without the BS firewall enabled,
> and check the BS log for a IP Spoofing messages.
> My theory here is that the BS is rejecting the spoofed IP
> on the internal LAN. The 'whois' or broadcast of the
> rejection packets back and forth may cause the BS to
> lock, or the BSMT. (most likely the BS, fixed by a reset).
>
>
> Raf
> MS fAN
>
>
>
> >-----Original Message-----
> >I do testing on my LAN for syn flooding to test one of

> the other PC's
> >firewalls --- I know the MN-700 has adequate firewall

> protection ... But
> >it's for peace of mind.
> >Anyway... I do this, Spoof the IP, etc, and it freezes

> the base station's
> >management tool? LOL ... I can ping it, ping past it,

> ping my other
> >computers, and ping web sites .... Everything works but

> the management tool
> >.... I don't get it. Why would the management tool even

> be involved?
> >
> >
> >.
> >



 
Reply With Quote
 
Steven E. Woolard
Guest
Posts: n/a

 
      02-11-2004, 09:28 AM
I did a little bit of wondering around ...
And I disabled spoofing ...
It worked. heh...
Router doesn't like spoofing -- I guess that's a good thing..
But why would it lock?!
Does it notice I'm spoofing and bans my MAC? Heh
If so, kickass, if not... damn
"Steven E. Woolard" <(E-Mail Removed)> wrote in message
news:FqlWb.20381$(E-Mail Removed) hlink.net...
> My thoughts were the firewall was flooded by the requests and therefore

took
> all available processing power (hence the lack of management tool) to

lookup
> the spoofed IP of the packet ... Or something along those lines. Problem

is,
> I cannot disable the firewall in the MN-700 --- Which really sucks.
>
>
> "Raf" <(E-Mail Removed)> wrote in message
> news:e30601c3f06b$0feaaa30$(E-Mail Removed)...
> > Hey,
> >
> > Interesting you point this out, because I've seen it
> > before. May want to try without the BS firewall enabled,
> > and check the BS log for a IP Spoofing messages.
> > My theory here is that the BS is rejecting the spoofed IP
> > on the internal LAN. The 'whois' or broadcast of the
> > rejection packets back and forth may cause the BS to
> > lock, or the BSMT. (most likely the BS, fixed by a reset).
> >
> >
> > Raf
> > MS fAN
> >
> >
> >
> > >-----Original Message-----
> > >I do testing on my LAN for syn flooding to test one of

> > the other PC's
> > >firewalls --- I know the MN-700 has adequate firewall

> > protection ... But
> > >it's for peace of mind.
> > >Anyway... I do this, Spoof the IP, etc, and it freezes

> > the base station's
> > >management tool? LOL ... I can ping it, ping past it,

> > ping my other
> > >computers, and ping web sites .... Everything works but

> > the management tool
> > >.... I don't get it. Why would the management tool even

> > be involved?
> > >
> > >
> > >.
> > >

>
>



 
Reply With Quote
 
Barb Bowman [MVP-Windows]
Guest
Posts: n/a

 
      02-11-2004, 10:02 AM
are you saying that if you do not clone the mac address of your pc
that the problem disappears?

On Wed, 11 Feb 2004 10:28:24 GMT, "Steven E. Woolard"
<(E-Mail Removed)> wrote:

>I did a little bit of wondering around ...
>And I disabled spoofing ...
>It worked. heh...
>Router doesn't like spoofing -- I guess that's a good thing..
>But why would it lock?!
>Does it notice I'm spoofing and bans my MAC? Heh
>If so, kickass, if not... damn
>"Steven E. Woolard" <(E-Mail Removed)> wrote in message
>news:FqlWb.20381$(E-Mail Removed) thlink.net...
>> My thoughts were the firewall was flooded by the requests and therefore

>took
>> all available processing power (hence the lack of management tool) to

>lookup
>> the spoofed IP of the packet ... Or something along those lines. Problem

>is,
>> I cannot disable the firewall in the MN-700 --- Which really sucks.
>>
>>
>> "Raf" <(E-Mail Removed)> wrote in message
>> news:e30601c3f06b$0feaaa30$(E-Mail Removed)...
>> > Hey,
>> >
>> > Interesting you point this out, because I've seen it
>> > before. May want to try without the BS firewall enabled,
>> > and check the BS log for a IP Spoofing messages.
>> > My theory here is that the BS is rejecting the spoofed IP
>> > on the internal LAN. The 'whois' or broadcast of the
>> > rejection packets back and forth may cause the BS to
>> > lock, or the BSMT. (most likely the BS, fixed by a reset).
>> >
>> >
>> > Raf
>> > MS fAN
>> >
>> >
>> >
>> > >-----Original Message-----
>> > >I do testing on my LAN for syn flooding to test one of
>> > the other PC's
>> > >firewalls --- I know the MN-700 has adequate firewall
>> > protection ... But
>> > >it's for peace of mind.
>> > >Anyway... I do this, Spoof the IP, etc, and it freezes
>> > the base station's
>> > >management tool? LOL ... I can ping it, ping past it,
>> > ping my other
>> > >computers, and ping web sites .... Everything works but
>> > the management tool
>> > >.... I don't get it. Why would the management tool even
>> > be involved?
>> > >
>> > >
>> > >.
>> > >

>>
>>

>


--
Barb Bowman
Expert Zone Columnist
http://www.microsoft.com/windowsxp/expertzone
MS-MVP (Windows)
 
Reply With Quote
 
Steven E. Woolard
Guest
Posts: n/a

 
      02-11-2004, 12:24 PM
I'm saying if I try to send a packet out of my router
with an external IP, it locks. Period.
No other machine on the LAN can ping it.
All traffic stops. No one can get on the web or access anything on the LAN.

"Barb Bowman [MVP-Windows]" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> are you saying that if you do not clone the mac address of your pc
> that the problem disappears?
>
> On Wed, 11 Feb 2004 10:28:24 GMT, "Steven E. Woolard"
> <(E-Mail Removed)> wrote:
>
> >I did a little bit of wondering around ...
> >And I disabled spoofing ...
> >It worked. heh...
> >Router doesn't like spoofing -- I guess that's a good thing..
> >But why would it lock?!
> >Does it notice I'm spoofing and bans my MAC? Heh
> >If so, kickass, if not... damn
> >"Steven E. Woolard" <(E-Mail Removed)> wrote in message
> >news:FqlWb.20381$(E-Mail Removed) thlink.net...
> >> My thoughts were the firewall was flooded by the requests and therefore

> >took
> >> all available processing power (hence the lack of management tool) to

> >lookup
> >> the spoofed IP of the packet ... Or something along those lines.

Problem
> >is,
> >> I cannot disable the firewall in the MN-700 --- Which really sucks.
> >>
> >>
> >> "Raf" <(E-Mail Removed)> wrote in message
> >> news:e30601c3f06b$0feaaa30$(E-Mail Removed)...
> >> > Hey,
> >> >
> >> > Interesting you point this out, because I've seen it
> >> > before. May want to try without the BS firewall enabled,
> >> > and check the BS log for a IP Spoofing messages.
> >> > My theory here is that the BS is rejecting the spoofed IP
> >> > on the internal LAN. The 'whois' or broadcast of the
> >> > rejection packets back and forth may cause the BS to
> >> > lock, or the BSMT. (most likely the BS, fixed by a reset).
> >> >
> >> >
> >> > Raf
> >> > MS fAN
> >> >
> >> >
> >> >
> >> > >-----Original Message-----
> >> > >I do testing on my LAN for syn flooding to test one of
> >> > the other PC's
> >> > >firewalls --- I know the MN-700 has adequate firewall
> >> > protection ... But
> >> > >it's for peace of mind.
> >> > >Anyway... I do this, Spoof the IP, etc, and it freezes
> >> > the base station's
> >> > >management tool? LOL ... I can ping it, ping past it,
> >> > ping my other
> >> > >computers, and ping web sites .... Everything works but
> >> > the management tool
> >> > >.... I don't get it. Why would the management tool even
> >> > be involved?
> >> > >
> >> > >
> >> > >.
> >> > >
> >>
> >>

> >

>
> --
> Barb Bowman
> Expert Zone Columnist
> http://www.microsoft.com/windowsxp/expertzone
> MS-MVP (Windows)



 
Reply With Quote
 
Barb Bowman \(MVP-Windows\)
Guest
Posts: n/a

 
      02-11-2004, 12:36 PM
why are you trying to send a packet with a spoofed external IP address?

Steven E. Woolard wrote:
> I'm saying if I try to send a packet out of my router
> with an external IP, it locks. Period.
> No other machine on the LAN can ping it.
> All traffic stops. No one can get on the web or access anything on
> the LAN.
>
> "Barb Bowman [MVP-Windows]" <(E-Mail Removed)> wrote in message
> news:(E-Mail Removed)...
>> are you saying that if you do not clone the mac address of your pc
>> that the problem disappears?
>>
>> On Wed, 11 Feb 2004 10:28:24 GMT, "Steven E. Woolard"
>> <(E-Mail Removed)> wrote:
>>
>>> I did a little bit of wondering around ...
>>> And I disabled spoofing ...
>>> It worked. heh...
>>> Router doesn't like spoofing -- I guess that's a good thing..
>>> But why would it lock?!
>>> Does it notice I'm spoofing and bans my MAC? Heh
>>> If so, kickass, if not... damn
>>> "Steven E. Woolard" <(E-Mail Removed)> wrote in message
>>> news:FqlWb.20381$(E-Mail Removed) hlink.net...
>>>> My thoughts were the firewall was flooded by the requests and
>>>> therefore took all available processing power (hence the lack of
>>>> management tool) to lookup the spoofed IP of the packet ... Or
>>>> something along those lines. Problem is,
>>> is,
>>>> I cannot disable the firewall in the MN-700 --- Which really sucks.
>>>>
>>>>
>>>> "Raf" <(E-Mail Removed)> wrote in message
>>>> news:e30601c3f06b$0feaaa30$(E-Mail Removed)...
>>>>> Hey,
>>>>>
>>>>> Interesting you point this out, because I've seen it
>>>>> before. May want to try without the BS firewall enabled,
>>>>> and check the BS log for a IP Spoofing messages.
>>>>> My theory here is that the BS is rejecting the spoofed IP
>>>>> on the internal LAN. The 'whois' or broadcast of the
>>>>> rejection packets back and forth may cause the BS to
>>>>> lock, or the BSMT. (most likely the BS, fixed by a reset).
>>>>>
>>>>>
>>>>> Raf
>>>>> MS fAN
>>>>>
>>>>>
>>>>>
>>>>>> -----Original Message-----
>>>>>> I do testing on my LAN for syn flooding to test one of the other
>>>>>> PC's firewalls --- I know the MN-700 has adequate firewall
>>>>>> protection ... But it's for peace of mind.
>>>>>> Anyway... I do this, Spoof the IP, etc, and it freezes the base
>>>>>> station's management tool? LOL ... I can ping it, ping past it,
>>>>>> ping my other computers, and ping web sites .... Everything
>>>>>> works but the management tool .... I don't get it. Why would the
>>>>>> management tool even be involved?
>>>>>>
>>>>>>
>>>>>> .
>>>>>>
>>>>
>>>>
>>>

>>
>> --
>> Barb Bowman
>> Expert Zone Columnist
>> http://www.microsoft.com/windowsxp/expertzone
>> MS-MVP (Windows)



--
Barb Bowman
Expert Zone Columnist
http://www.microsoft.com/windowsxp/expertzone
MS-MVP (Windows)


 
Reply With Quote
 
Steven E. Woolard
Guest
Posts: n/a

 
      02-11-2004, 02:02 PM
It's explained in the first post.
And out of all seriousness, it is done legally with permission.


"Barb Bowman (MVP-Windows)" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> why are you trying to send a packet with a spoofed external IP address?
>
> Steven E. Woolard wrote:
> > I'm saying if I try to send a packet out of my router
> > with an external IP, it locks. Period.
> > No other machine on the LAN can ping it.
> > All traffic stops. No one can get on the web or access anything on
> > the LAN.
> >
> > "Barb Bowman [MVP-Windows]" <(E-Mail Removed)> wrote in message
> > news:(E-Mail Removed)...
> >> are you saying that if you do not clone the mac address of your pc
> >> that the problem disappears?
> >>
> >> On Wed, 11 Feb 2004 10:28:24 GMT, "Steven E. Woolard"
> >> <(E-Mail Removed)> wrote:
> >>
> >>> I did a little bit of wondering around ...
> >>> And I disabled spoofing ...
> >>> It worked. heh...
> >>> Router doesn't like spoofing -- I guess that's a good thing..
> >>> But why would it lock?!
> >>> Does it notice I'm spoofing and bans my MAC? Heh
> >>> If so, kickass, if not... damn
> >>> "Steven E. Woolard" <(E-Mail Removed)> wrote in message
> >>> news:FqlWb.20381$(E-Mail Removed) hlink.net...
> >>>> My thoughts were the firewall was flooded by the requests and
> >>>> therefore took all available processing power (hence the lack of
> >>>> management tool) to lookup the spoofed IP of the packet ... Or
> >>>> something along those lines. Problem is,
> >>> is,
> >>>> I cannot disable the firewall in the MN-700 --- Which really sucks.
> >>>>
> >>>>
> >>>> "Raf" <(E-Mail Removed)> wrote in message
> >>>> news:e30601c3f06b$0feaaa30$(E-Mail Removed)...
> >>>>> Hey,
> >>>>>
> >>>>> Interesting you point this out, because I've seen it
> >>>>> before. May want to try without the BS firewall enabled,
> >>>>> and check the BS log for a IP Spoofing messages.
> >>>>> My theory here is that the BS is rejecting the spoofed IP
> >>>>> on the internal LAN. The 'whois' or broadcast of the
> >>>>> rejection packets back and forth may cause the BS to
> >>>>> lock, or the BSMT. (most likely the BS, fixed by a reset).
> >>>>>
> >>>>>
> >>>>> Raf
> >>>>> MS fAN
> >>>>>
> >>>>>
> >>>>>
> >>>>>> -----Original Message-----
> >>>>>> I do testing on my LAN for syn flooding to test one of the other
> >>>>>> PC's firewalls --- I know the MN-700 has adequate firewall
> >>>>>> protection ... But it's for peace of mind.
> >>>>>> Anyway... I do this, Spoof the IP, etc, and it freezes the base
> >>>>>> station's management tool? LOL ... I can ping it, ping past it,
> >>>>>> ping my other computers, and ping web sites .... Everything
> >>>>>> works but the management tool .... I don't get it. Why would the
> >>>>>> management tool even be involved?
> >>>>>>
> >>>>>>
> >>>>>> .
> >>>>>>
> >>>>
> >>>>
> >>>
> >>
> >> --
> >> Barb Bowman
> >> Expert Zone Columnist
> >> http://www.microsoft.com/windowsxp/expertzone
> >> MS-MVP (Windows)

>
>
> --
> Barb Bowman
> Expert Zone Columnist
> http://www.microsoft.com/windowsxp/expertzone
> MS-MVP (Windows)
>
>



 
Reply With Quote
 
Raf
Guest
Posts: n/a

 
      02-11-2004, 05:36 PM
Hi Steven,

Ya, sorry about that. Slipped my mind about the mn-700
firewall not a option. But its obvious the BS doesn't like
the spoofed IP address here (obviously for maybe the same
reason a switch wouldn't like the spoofed IP, as it doesn't
match up in the arp cache or its address table).
Like I said, you'll prob see Spoofing reports in the BS log.

Best of luck
Raf


>-----Original Message-----
>It's explained in the first post.
>And out of all seriousness, it is done legally with

permission.
>
>
>"Barb Bowman (MVP-Windows)" <(E-Mail Removed)> wrote in message
>news:(E-Mail Removed)...
>> why are you trying to send a packet with a spoofed

external IP address?
>>
>> Steven E. Woolard wrote:
>> > I'm saying if I try to send a packet out of my router
>> > with an external IP, it locks. Period.
>> > No other machine on the LAN can ping it.
>> > All traffic stops. No one can get on the web or access

anything on
>> > the LAN.
>> >
>> > "Barb Bowman [MVP-Windows]" <(E-Mail Removed)> wrote in

message
>> > news:(E-Mail Removed)...
>> >> are you saying that if you do not clone the mac

address of your pc
>> >> that the problem disappears?
>> >>
>> >> On Wed, 11 Feb 2004 10:28:24 GMT, "Steven E. Woolard"
>> >> <(E-Mail Removed)> wrote:
>> >>
>> >>> I did a little bit of wondering around ...
>> >>> And I disabled spoofing ...
>> >>> It worked. heh...
>> >>> Router doesn't like spoofing -- I guess that's a

good thing..
>> >>> But why would it lock?!
>> >>> Does it notice I'm spoofing and bans my MAC? Heh
>> >>> If so, kickass, if not... damn
>> >>> "Steven E. Woolard" <(E-Mail Removed)> wrote in

message
>> >>>

news:FqlWb.20381$(E-Mail Removed) hlink.net...
>> >>>> My thoughts were the firewall was flooded by the

requests and
>> >>>> therefore took all available processing power

(hence the lack of
>> >>>> management tool) to lookup the spoofed IP of the

packet ... Or
>> >>>> something along those lines. Problem is,
>> >>> is,
>> >>>> I cannot disable the firewall in the MN-700 ---

Which really sucks.
>> >>>>
>> >>>>
>> >>>> "Raf" <(E-Mail Removed)> wrote in message
>> >>>> news:e30601c3f06b$0feaaa30$(E-Mail Removed)...
>> >>>>> Hey,
>> >>>>>
>> >>>>> Interesting you point this out, because I've seen it
>> >>>>> before. May want to try without the BS firewall

enabled,
>> >>>>> and check the BS log for a IP Spoofing messages.
>> >>>>> My theory here is that the BS is rejecting the

spoofed IP
>> >>>>> on the internal LAN. The 'whois' or broadcast of the
>> >>>>> rejection packets back and forth may cause the BS to
>> >>>>> lock, or the BSMT. (most likely the BS, fixed by a

reset).
>> >>>>>
>> >>>>>
>> >>>>> Raf
>> >>>>> MS fAN
>> >>>>>
>> >>>>>
>> >>>>>
>> >>>>>> -----Original Message-----
>> >>>>>> I do testing on my LAN for syn flooding to test

one of the other
>> >>>>>> PC's firewalls --- I know the MN-700 has adequate

firewall
>> >>>>>> protection ... But it's for peace of mind.
>> >>>>>> Anyway... I do this, Spoof the IP, etc, and it

freezes the base
>> >>>>>> station's management tool? LOL ... I can ping it,

ping past it,
>> >>>>>> ping my other computers, and ping web sites ....

Everything
>> >>>>>> works but the management tool .... I don't get

it. Why would the
>> >>>>>> management tool even be involved?
>> >>>>>>
>> >>>>>>
>> >>>>>> .
>> >>>>>>
>> >>>>
>> >>>>
>> >>>
>> >>
>> >> --
>> >> Barb Bowman
>> >> Expert Zone Columnist
>> >> http://www.microsoft.com/windowsxp/expertzone
>> >> MS-MVP (Windows)

>>
>>
>> --
>> Barb Bowman
>> Expert Zone Columnist
>> http://www.microsoft.com/windowsxp/expertzone
>> MS-MVP (Windows)
>>
>>

>
>
>.
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
MN 700 Management Tool =?Utf-8?B?QWwgRnJhbg==?= Broadband Hardware 1 12-31-2005 02:51 PM
management tool Robert Broadband Hardware 1 04-17-2005 07:33 PM
Management tool in BBN Jake Broadband Hardware 5 11-04-2004 05:22 AM
Management tool MN 700 Bodo Broadband Hardware 2 06-06-2004 04:16 PM
Management tool bodo Broadband Hardware 0 06-05-2004 02:39 AM



1 2 3 4 5 6 7 8 9 10 11