mhchs Posted March 2, 2010 Posted March 2, 2010 (edited) Hi i am having problems with loads of trash packets being sent to the default gateway which then slows the network right down. our isp / lea people are saying that they are getting loads of packets from the following address 127.0.0.1 obv this is the address that you ping to check the local nic so i cant just do a quick search for it and then go and kill the device. or is there??? this is causing the network to slow down and causing the internet to freeze and hang also i have noticed lag in exploring the network caused by this back log of packets on the line. at the moment im switching off a building at a time and then having to call them back to see if they are still getting the packets. this work can only be done out of hours and only till 6pm as they go home so as you can guess this is a very slow!! does any one know of a faster way of doing this or how i can search to find out where this is coming from?? Edited March 2, 2010 by mhchs
glennda Posted March 2, 2010 Posted March 2, 2010 try running this Wireshark About also do you have an ISA server in the middle between your network and there default gateway?
mattx Posted March 2, 2010 Posted March 2, 2010 Ethereal is another... Ethereal: A Network Protocol Analyzer
mhchs Posted March 2, 2010 Author Posted March 2, 2010 Hi ok thanks i will try this out tomorrow. i have seen this being used before but im not quite sure how to set up the capture?? yeah there is an isa server but its more used for checking people coming in through to our web mail server, can i still use it to track this down then??
glennda Posted March 2, 2010 Posted March 2, 2010 Hi ok thanks i will try this out tomorrow. i have seen this being used before but im not quite sure how to set up the capture?? yeah there is an isa server but its more used for checking people coming in through to our web mail server, can i still use it to track this down then?? hmm, it depends how you have it set up, at my place we have it physically between us and the internet so nic 1 is lan nic 2 is wan, if it is set up like that (might be possible if not). without connecting to it from here ( which i can't as i can't get the vpn client working on my linux box!) theres an option to view a live log and you can set filters up etc to limit what is being shown. i would suggest tho that if its sending masses of packets that its some type of virus. as for setting up wireshark to look theres a video available Wireshark Introduction
AngryTechnician Posted March 2, 2010 Posted March 2, 2010 Ethereal is another... Ethereal is what Wireshark used to be called before they changed the name. I'm surprised the site is even still there, but although it hasn't been updated in years, the SourceForge download links take you to the Wireshark project page.
mattx Posted March 2, 2010 Posted March 2, 2010 Hi ok thanks i will try this out tomorrow. i have seen this being used before but im not quite sure how to set up the capture?? yeah there is an isa server but its more used for checking people coming in through to our web mail server, can i still use it to track this down then?? I suggest you have a quick read through the FAQs / Instructions - capture a 10 second blast on a segment of your network where you know you are getting problems - then post the data [ zip it up as it will be quite large ] and let a few people look at the data - you may get a few conflicting results from people but I am sure one or two of us will agree.....
mattx Posted March 2, 2010 Posted March 2, 2010 Ethereal is what Wireshark used to be called before they changed the name. I'm surprised the site is even still there, but although it hasn't been updated in years, the SourceForge download links take you to the Wireshark project page. Fair enough, just proves how old I am when it comes to using certain applications !!!
mhchs Posted March 2, 2010 Author Posted March 2, 2010 excellent, nice one everybody i will give it a go and post up what i find. thanks
glennda Posted March 2, 2010 Posted March 2, 2010 also check your anti-virus server as it may have picked things up that you don't want - but hasn't installed properly on the machine that is sending the packets - also check domain controllers for mass failed login attempts
timzim Posted March 3, 2010 Posted March 3, 2010 If you have ISA 2006, as long as you have ISA Server 2006 Supportability Update (KB939455) applied to your ISA server you can use the Log Viewer (Logging tab in Monitoring) to filter and view all traffic in the logs - doesn't have to be live data: just change the Log Time from "Live" to whatever interval you want to examine.
mhchs Posted March 4, 2010 Author Posted March 4, 2010 Hi work was mental so i didnt get to do it yesterday. just done my first capture but cant make head nor tail of it i have attached the file can any one make sense of this??first trial catch 04032010.zip
mac_shinobi Posted March 4, 2010 Posted March 4, 2010 Ethereal is what Wireshark used to be called before they changed the name. I'm surprised the site is even still there, but although it hasn't been updated in years, the SourceForge download links take you to the Wireshark project page. mattx - say hello to the future , future say hello to mattx - as above its now wire shark which as angrytech stated above.
mhchs Posted March 4, 2010 Author Posted March 4, 2010 just a quick one this is the reports that our isp is giving us Inuse Entries: 43 Perm Entries: 0 Pending Entries: 0 Out Request: 14 Out Response: 0 In Request: 156 In Response: 14 Proxy Answered: 0 Rx Error: 0 Dup IP Addr: 0 Rejected count: 5 Rejected IP: 127.0.0.1 Rejected Port: 2 Rejected I/F: bnt-mhh-cu
m25man Posted March 4, 2010 Posted March 4, 2010 just done my first capture but cant make head nor tail of it i have attached the file can any one make sense of this?? I couldn't read it, what did you save it as?
mac_shinobi Posted March 4, 2010 Posted March 4, 2010 prolly a daft thought so appologies in advance to the OP and everyone else You haven't setup or configured a web server anywhere have you ie IIS or apache ?? That or a duff / dead network card ??
mattx Posted March 4, 2010 Posted March 4, 2010 (edited) Just had a quick look..... Lots of ARP requests...... Also frame 178 has me a little confused. Is that a switch looking for 127.0.0.1 ? As it's pointing to another switch which states it's the same address ? It's as if they are fighting it out between themselves. Also Sophos is looking for something on a different subnet !! Edited March 4, 2010 by mattx
mhchs Posted March 4, 2010 Author Posted March 4, 2010 i have several iis servers running different web apps. i also have got vmware
mattx Posted March 4, 2010 Posted March 4, 2010 (edited) Need someone else to back me up but I would look at the configs of the two switches - Netgear ? [ if they are switches ] of frames 178 & 160 - [ the mac addresses are in the capture file ] Edited March 4, 2010 by mattx
mhchs Posted March 4, 2010 Author Posted March 4, 2010 hi i missed that when i looked at it the first time round. nice one i have looked at it again and tracked the device it is a WAP. i went and killed the wap and the switch that its connected to i then run a second scan [ the one attached] i then checked through the logs and noticed it appearing on the next wap in the area and the one next to that and the one next to that...and theone next to that! they are on frames 96,99,126,137 do you think i may have a rogue wireless device or outside device???second.zip
glennda Posted March 4, 2010 Posted March 4, 2010 (edited) do you wap have a controller? or are they unmanaged? Edit: what has the addresses that 127.0.0.1 is trying to look up? for the second round its 10.11.71.103 10.11.71.116 10.11.71.107 10.11.71.114 Edited March 4, 2010 by glennda
mhchs Posted March 12, 2010 Author Posted March 12, 2010 Hi thanks for all the replies i have sorted this out now. it seems that aload of the waps have reset and the firm ware has been trashed so im now in the process of redoing all of them.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now