new cust. getting weird UDP hits on firewall
04-10-2006, 15:23
|
#1
|
Inactive
Join Date: Aug 2006
Posts: 40
|
new cust. getting weird UDP hits on firewall
Firewall showing frequent (blocked) UDP access attempts coming from 10.247.4.1.bootps trying to reach local access point 255.255.255.255.bootpc.
Arin tells me the 10. address is reserved for 'private internet' so I ASS-U-ME that the orgin is actually NTL....
Anyone else seeing this ? or can shed some light on it ?
(If it is NTL I suspect it is DHCP related...)
|
|
|
04-10-2006, 15:27
|
#2
|
Inactive
Join Date: Jun 2003
Location: Essex innit
Age: 51
Services: Sky HD + 16Mb ADSL
BT Telephone
Posts: 15,735
|
Re: new cust. getting weird UDP hits on firewall
Are you letting your DHCP and DNS servers IP addresses through?
|
|
|
04-10-2006, 15:36
|
#3
|
Inactive
Join Date: Aug 2006
Posts: 40
|
Re: new cust. getting weird UDP hits on firewall
That was quick - many thanks.
So you agree with the DHCP thing ?
I don't run DNS locally (on windows) - have a large hosts file and it slows down windows at first net access. no sweat as the remote service works.
I made no change to firewall rules when I went broadband. Just had to changee the windows services setup to start DHCP service. I don't run all the windows services automatically. As the install went okay and I am on the network I have to take it that the DHCP 'connection' is working ! but then again I am not a network guy...
|
|
|
04-10-2006, 15:44
|
#4
|
Inactive
Join Date: Jan 2006
Location: Berkshire
Posts: 1,266
|
Re: new cust. getting weird UDP hits on firewall
There are folks on here who know better than I, but that looks more like a general broadcast from a node somewhere in the NTL network rather than anything specifically directed at your PC.
More specifically a BootP Server - I thought these generally created a shed load of noise on LANs and were bad things to have unless they were in a restricted private LAN but hey, what do I know...
|
|
|
04-10-2006, 16:59
|
#5
|
Inactive
Join Date: Aug 2006
Posts: 40
|
Re: new cust. getting weird UDP hits on firewall
You know more than I do !!
But why they go for UDP when it is deprecated and or closed off by so many....
|
|
|
04-10-2006, 17:06
|
#6
|
-
Join Date: Jul 2003
Location: Poole, Dorset
Age: 40
Services: FreeSat+
Tivo
V-Box
VM 60MBit
Posts: 13,365
|
Re: new cust. getting weird UDP hits on firewall
Quote:
Originally Posted by bamabama
But why they go for UDP when it is deprecated and or closed off by so many....
|
Eh!? I hope not...
UDP is used by Streaming Media, VoIP, Online Games, and many more important parts of the internet that help it function!
|
|
|
04-10-2006, 17:22
|
#7
|
Inactive
Join Date: Aug 2006
Posts: 40
|
Re: new cust. getting weird UDP hits on firewall
Yep. I should have gone in to more detail.
Several UDP ports need to be closed off/set correctky to avoid exposures.
Closing off UDP in general and then allowing (drilling through) individual ports with associated program pathing controls for specfic application(s) is perfectly valid and a good method IMV.
|
|
|
04-10-2006, 19:23
|
#8
|
Inactive
Join Date: Jul 2006
Location: Sutton-In-Ashfield
Age: 47
Services: C#/ASP.NET Web Development
Posts: 3,580
|
Re: new cust. getting weird UDP hits on firewall
Quote:
Originally Posted by bamabama
You know more than I do !!
But why they go for UDP when it is deprecated and or closed off by so many....
|
TCP is a very expensive (in terms of resources/performance) as it has to maintain connections and make sure that data gets to where it's supposed to be, and in the correct order. UDP is connectionless and does not have the same overheads as TCP (but with down sides like packet loss unless controlled) and is used by a whole host of applications.
As an example, I play Spearhead and Call Of Duty online. The RCON (Remote CONsole) for controlling the server uses UDP.
---------- Post added at 19:23 ---------- Previous post was at 19:22 ----------
Quote:
Originally Posted by bamabama
Yep. I should have gone in to more detail.
Several UDP ports need to be closed off/set correctky to avoid exposures.
Closing off UDP in general and then allowing (drilling through) individual ports with associated program pathing controls for specfic application(s) is perfectly valid and a good method IMV.
|
Fair point also lol
|
|
|
04-10-2006, 19:26
|
#9
|
-
Join Date: Jul 2003
Location: Poole, Dorset
Age: 40
Services: FreeSat+
Tivo
V-Box
VM 60MBit
Posts: 13,365
|
Re: new cust. getting weird UDP hits on firewall
Quote:
Originally Posted by AntiSilence
The RCON (Remote CONsole) for controlling the server uses UDP.
|
You'll probably find it's the same protocol as used for the game->game server transactions as well
|
|
|
04-10-2006, 19:29
|
#10
|
Inactive
Join Date: Jul 2006
Location: Sutton-In-Ashfield
Age: 47
Services: C#/ASP.NET Web Development
Posts: 3,580
|
Re: new cust. getting weird UDP hits on firewall
Quote:
Originally Posted by Zeph
You'll probably find it's the same protocol as used for the game->game server transactions as well
|
I've never actually checked that before. I do know that EA Games use a code sequence at the beginning of the RCON command, otherwise the game server ignores it! I was making a Windows RCON app and I had to figure it out!
|
|
|
27-04-2009, 16:10
|
#11
|
Inactive
Join Date: Apr 2009
Posts: 2
|
Re: new cust. getting weird UDP hits on firewall
Guys
1st post from me in this forum!
I too am seeing loads of hits from my cable modem, like every 0.5-10 seconds.
They are UDP traffic from my modem's IP on port 67 (bootps/DHCP server) to destination 255.255.255.255 destination port 68 (bootpc).
Can anyone say if this is a problem? I just today received a replacement modem from Virgin, it's doing exactly the same thing.
Also.... my neighbour does not see this problem on his network.
At this stage I don't know if it's related but I also suffer from sporadic wireless restarts.
thanks
Paul
|
|
|
28-04-2009, 22:37
|
#12
|
Inactive
Join Date: Mar 2004
Services: BB:M, TV:XL, Phone:M, Loyalty
Posts: 2,516
|
Re: new cust. getting weird UDP hits on firewall
Holy thread resurrection Batman!
And yes, it IS DCHP.
There are two modes of DCHP, the initial broadcast mode, where a system with no address broadcasts a request, and the DHCP server (or on most cable, the UBR private address acting as a DHCP proxy) responds by broadcast.
The second mode is renewal, directed to the DHCP server which is now known.
|
|
|
29-04-2009, 16:28
|
#13
|
Inactive
Join Date: Apr 2009
Posts: 2
|
Re: new cust. getting weird UDP hits on firewall
Thanks for making me laugh.
All of the devices which connect through my router have a valid IP address, but I see this continual stream of requests all day every day.
How can I discover why this is happening?
thanks
|
|
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT +1. The time now is 07:49.
|