Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Firewall spots continuous traffic

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Virgin Media Services > Virgin Media Internet Service
Register FAQ Community Calendar

Firewall spots continuous traffic
Reply
 
Thread Tools
Old 12-06-2004, 16:56   #1
kenseaton
Inactive
 
Join Date: Apr 2004
Posts: 49
kenseaton is an unknown quantity at this point
Firewall spots continuous traffic

Hi

I'm using Sygate personal firewall and over the past month I've noticed that the icon is showing a virtually permanant contact with address 172.31.55.254. It back traces to blackhole-1.iana.org at IANA and ntl customer support says its just a sign of increased email traffic.
However ... I don't like something going on that I don't know about and I wondered if anyone had any clues. I'm seeing incoming traffic history registering 54-600B virtually constantly.

thanks

Ken
Glasgow
kenseaton is offline   Reply With Quote
Advertisement
Old 12-06-2004, 17:02   #2
Chris W
cf.mega poster
 
Join Date: Nov 2003
Location: Reading
Age: 41
Services: Virgin Media Broadband Size M
Posts: 6,546
Chris W has a nice shiny star
Chris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny star
Send a message via MSN to Chris W
Re: Firewall spots continuous traffic

to the site!

I am not sure if you can do it with sygate, but can you configure the firewall to block connections to 172.31.55.254?

It sounds like some kind of spyware on the pc is trying to connect to this, run adaware (http://tinyurl.com/tek5) to clear any spware from the pc
Chris W is offline   Reply With Quote
Old 12-06-2004, 17:30   #3
Tricky
Inactive
 
Tricky's Avatar
 
Join Date: Jun 2003
Location: I am house...
Services: $KY+HD - BT Infinity
Posts: 2,284
Tricky is the helpful oneTricky is the helpful oneTricky is the helpful oneTricky is the helpful oneTricky is the helpful oneTricky is the helpful oneTricky is the helpful oneTricky is the helpful oneTricky is the helpful oneTricky is the helpful oneTricky is the helpful oneTricky is the helpful oneTricky is the helpful oneTricky is the helpful oneTricky is the helpful oneTricky is the helpful oneTricky is the helpful one
Re: Firewall spots continuous traffic

172.16.0.0 --> 172.31.255.255 are generally used for private networks within orgs. (172.16.x.x especially if your network was designed by BT - which is great when two companies merge!)

Have you created any VPN's back to your office or anything that might still be trying to connect out/in?
Are you running anything else that might be causing the traffic?
Tricky is offline   Reply With Quote
Old 12-06-2004, 19:08   #4
Paul
Dr Pepper Addict
Cable Forum Admin
 
Paul's Avatar
 
Join Date: Oct 2003
Location: Nottingham
Age: 63
Services: IDNet FTTP (1000M), Sky Q TV, Sky Mobile, Flextel SIP
Posts: 30,666
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Re: Firewall spots continuous traffic

Quote:
Originally Posted by kenseaton
Hi

I'm using Sygate personal firewall and over the past month I've noticed that the icon is showing a virtually permanant contact with address 172.31.55.254. It back traces to blackhole-1.iana.org at IANA and ntl customer support says its just a sign of increased email traffic.
However ... I don't like something going on that I don't know about and I wondered if anyone had any clues. I'm seeing incoming traffic history registering 54-600B virtually constantly.

thanks

Ken
Glasgow
At a guess I would say that is probably your ubr's default gateway private address - and the traffic is genuine local broadcast packets. Try pinging it - if you can that would be futher evidence that this is, in fact, the explanation.

Edit : even better - do a tracert to cableforum.co.uk and see if this address is one of the first hops.
__________________

Baby, I was born this way.
Paul is offline   Reply With Quote
Old 13-06-2004, 12:28   #5
kenseaton
Inactive
 
Join Date: Apr 2004
Posts: 49
kenseaton is an unknown quantity at this point
Re: Firewall spots continuous traffic

Quote:
Originally Posted by Pem
At a guess I would say that is probably your ubr's default gateway private address - and the traffic is genuine local broadcast packets. Try pinging it - if you can that would be futher evidence that this is, in fact, the explanation.

Edit : even better - do a tracert to cableforum.co.uk and see if this address is one of the first hops.


OK here's the tracert detail (below) and, as you say, the 173 address is the first hop... what I don't understand is why it's showing up on the Syquest traffic log all the time, especially as it's only been happening over the past month or so.

Ken

>>
Tracing route to cableforum.co.uk [66.199.235.18]
over a maximum of 30 hops:

1 27 ms 14 ms 14 ms 172.31.55.254
2 14 ms 27 ms <10 ms renf-t2cam1-a-v111.inet.ntl.com [80.4.64.
3 14 ms 13 ms 14 ms renf-t2core-a-ge-wan61.inet.ntl.com [62.2
57]
4 14 ms 14 ms 13 ms ren-bb-a-so-200-0.inet.ntl.com [62.253.18
5 <10 ms 13 ms 28 ms ren-bb-b-ae0-0.inet.ntl.com [62.253.185.1
6 14 ms 28 ms 13 ms man-bb-a-so-600-0.inet.ntl.com [62.253.18

7 28 ms 41 ms 28 ms ycr2-so-3-0-0.Manchester.cw.net [208.175.

8 27 ms 28 ms 27 ms bcr2-so-3-0-0.Thamesside.cw.net [166.63.2

9 96 ms 110 ms 137 ms dcr1.nyk.cw.net [195.2.1.3]
10 96 ms 110 ms 96 ms so-0-0-0-ecr1.nyk.cw.net [195.2.3.14]
11 96 ms 96 ms 96 ms nyiix.ezzi.net [198.32.160.106]
12 110 ms 96 ms 96 ms 65.125.239.41
13 110 ms 96 ms 97 ms 65.125.239.129
14 * * * Request timed out.
15 * * * Request timed out.
16 * * * Request timed out.
17 * *
<<
kenseaton is offline   Reply With Quote
Old 13-06-2004, 13:54   #6
BBKing
R.I.P.
 
BBKing's Avatar
 
Join Date: Jun 2003
Location: London
Services: 20Mb VM CM, Virgin TV
Posts: 5,983
BBKing has a nice shiny starBBKing has a nice shiny starBBKing has a nice shiny starBBKing has a nice shiny starBBKing has a nice shiny star
BBKing has a nice shiny starBBKing has a nice shiny starBBKing has a nice shiny starBBKing has a nice shiny starBBKing has a nice shiny starBBKing has a nice shiny starBBKing has a nice shiny starBBKing has a nice shiny starBBKing has a nice shiny star
Send a message via ICQ to BBKing
Re: Firewall spots continuous traffic

Firstly a bit of education. Addresses starting 172.16 to 172.31, 192.168 or 10 are *private* addresses. This means companies or individuals can use them internally but they are not reachable from outside the company. NTL use the 10 and 172.16-31 ranges for addressing your cable modem, since there's no reason why the modem itself should be accessible from outside ntl.

Thus 172.16.55.254 is a private non-routable address used on the ntl network. In fact, it's the default gateway for your cable modem and just happens to be the first address on your local UBR (the device that connects you to the Internet). Thus it is used as the source for any traffic the UBR sends to your PC, including DHCP renewals.

Robin Walker in his cable modem notes recommends allowing this IP address through the firewall. There's certainly nothing to worry about.
BBKing is offline   Reply With Quote
Old 13-06-2004, 20:15   #7
Matth
Inactive
 
Join Date: Mar 2004
Services: BB:M, TV:XL, Phone:M, Loyalty
Posts: 2,516
Matth has reached the bronze age
Matth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze age
Re: Firewall spots continuous traffic

UDP traffic?
I see a lot of broadcast DHCP traffic from my UBR - at first, with my firewall identifying is as DHCP, I thought MY system was generating abnormal amounts of DHCP (since the rule called it OUTGOING DHCP), but showing more of the logging parameters identified it as broadcast FROM the UBR.

On startup, you broadcast a DHCP request, the UBR forwards it to the DHCP, and then broadcasts the reply - and you receive all broadcast traffic.
Matth is offline   Reply With Quote
Old 13-06-2004, 21:47   #8
kenseaton
Inactive
 
Join Date: Apr 2004
Posts: 49
kenseaton is an unknown quantity at this point
Re: Firewall spots continuous traffic

OK ... I get all that, but why is the traffic signal continuous?

And why has it only just started?

The Sygate arrows did not show the same traffic two months ago ... and a Google search shows blackhole-1 etc as a catch-all for email snafus.

Ken
kenseaton is offline   Reply With Quote
Old 17-06-2004, 15:44   #9
kenseaton
Inactive
 
Join Date: Apr 2004
Posts: 49
kenseaton is an unknown quantity at this point
Re: Firewall spots continuous traffic

Curiously, since I started this post the continuous traffic has ceased...
kenseaton is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 12:39.


Server: lithium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum