Re: IPX broadcast forwarding in 2.4.1 kernels

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



> 20:39:10.940964 0:0:c0:94:82:e8 > Broadcast sap e0 ui/C
> >>> Unknown IPX Data: (51 bytes)
> [000] FF FF 00 50 00 14 00 00  00 00 FF FF FF FF FF FF  ...P.... ........
> [010] 04 55 00 1D 80 22 00 00  C0 94 82 E8 04 55 00 01  .U...".. .....U..
> [020] 00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  ........ ........
> [030] 00 00 00                                          ... 
>  len=81

Here we go. NETBIOS broadcast...

> 20:39:11.481675 0:0:c0:94:82:e8 > Broadcast sap e0 ui/C
> >>> Unknown IPX Data: (51 bytes)
> [000] FF FF 00 50 00 14 00 00  00 00 FF FF FF FF FF FF  ...P.... ........
> [010] 04 55 00 1D 80 22 00 00  C0 94 82 E8 04 55 00 01  .U...".. .....U..
> [020] 00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  ........ ........
> [030] 00 00 00                                          ... 
>  len=81

Another NETBIOS broadcast...

> 20:39:12.623150 0:0:c0:94:82:e8 > Broadcast sap e0 ui/C
> >>> Unknown IPX Data: (51 bytes)
> [000] FF FF 00 50 00 14 00 00  00 00 FF FF FF FF FF FF  ...P.... ........
> [010] 04 55 00 1D 80 22 00 00  C0 94 82 E8 04 55 00 01  .U...".. .....U..
> [020] 00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  ........ ........
> [030] 00 00 00                                          ... 
>  len=81

Once more. Who is 00:00:C0:94:82:E8?

> 20:39:13.163848 0:0:c0:94:82:e8 > Broadcast sap e0 ui/C
> >>> Unknown IPX Data: (51 bytes)
> [000] FF FF 00 50 00 14 00 00  00 00 FF FF FF FF FF FF  ...P.... ........
> [010] 04 55 00 1D 80 22 00 00  C0 94 82 E8 04 55 00 01  .U...".. .....U..
> [020] 00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  ........ ........
> [030] 00 00 00                                          ... 
>  len=81

...

> 20:39:14.723898 8:0:9:b9:1e:e8 > Broadcast sap aa ui/C
> >>> Unknown IPX Data: (35 bytes)
> [000] 22 00 00 00 00 00 00 FF  FF FF FF FF FF 04 52 00  "....... ......R.
> [010] 00 00 00 08 00 09 B9 1E  E8 40 0B 00 01 00 04 30  ........ .@.....0
> [020] 38 30 30                                          800 
>  len=35

tcpdump mishandles SNAP :-(((

> 20:39:15.611346 0:c0:f0:40:4f:13 > 0:a0:c9:69:9e:4c sap e0 ui/C
> >>> Unknown IPX Data: (51 bytes)
> [000] FF FF 00 3A 00 11 00 1D  20 05 00 00 00 00 00 01  ...:....  .......
> [010] 04 51 00 1D 80 22 00 C0  F0 40 4F 13 40 02 22 22  .Q...".. .@O.@.""
> [020] 59 1B 08 00 57 03 04 00  06 00 8D 05 00 00 02 A1  Y...W... ........
> [030] BD 02 00                                          ... 
>  len=58

... someone doing something on NCP ...

> 20:39:17.429993 0:e0:29:9:ca:6a > Broadcast sap e0 ui/C
> >>> Unknown IPX Data: (51 bytes)
> [000] FF FF 00 50 00 14 00 00  00 00 FF FF FF FF FF FF  ...P.... ........
> [010] 04 55 00 1D 80 22 00 E0  29 09 CA 6A 04 55 00 01  .U...".. )..j.U..
> [020] 00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  ........ ........
> [030] 00 00 00                                          ... 
>  len=81

... netbios...

I did not found anything wrong in this log. Windows machines broadcasts from
time to time, but nobody floods network... Maybe except 00:00:C0:94:82:E8.
Is it some router?
							Petr Vandrovec
							vandrove@vc.cvut.cz

-
: send the line "unsubscribe linux-net" in
the body of a message to majordomo@vger.kernel.org


[Index of Archives]     [Netdev]     [Ethernet Bridging]     [Linux 802.1Q VLAN]     [Linux Wireless]     [Kernel Newbies]     [Security]     [Linux for Hams]     [Netfilter]     [Git]     [Bugtraq]     [Yosemite News and Information]     [MIPS Linux]     [ARM Linux]     [Linux RAID]     [Linux PCI]     [Linux Admin]     [Samba]

  Powered by Linux