Jump to content

Recommended Posts

Posted (edited)

Hi

 

i am having problems with loads of trash packets being sent to the default gateway which then slows the network right down. our isp / lea people are saying that they are getting loads of packets from the following address 127.0.0.1

 

obv this is the address that you ping to check the local nic so i cant just do a quick search for it and then go and kill the device. or is there???

 

this is causing the network to slow down and causing the internet to freeze and hang also i have noticed lag in exploring the network caused by this back log of packets on the line.

 

 

at the moment im switching off a building at a time and then having to call them back to see if they are still getting the packets. this work can only be done out of hours and only till 6pm as they go home so as you can guess this is a very slow!!

 

does any one know of a faster way of doing this or how i can search to find out where this is coming from??

Edited by mhchs
Posted

Hi

 

ok thanks i will try this out tomorrow. i have seen this being used before but im not quite sure how to set up the capture??:confused:

 

yeah there is an isa server but its more used for checking people coming in through to our web mail server, can i still use it to track this down then??

Posted
Hi

 

ok thanks i will try this out tomorrow. i have seen this being used before but im not quite sure how to set up the capture??:confused:

 

yeah there is an isa server but its more used for checking people coming in through to our web mail server, can i still use it to track this down then??

 

hmm, it depends how you have it set up, at my place we have it physically between us and the internet so nic 1 is lan nic 2 is wan, if it is set up like that (might be possible if not). without connecting to it from here ( which i can't as i can't get the vpn client working on my linux box!) theres an option to view a live log and you can set filters up etc to limit what is being shown. i would suggest tho that if its sending masses of packets that its some type of virus.

 

 

as for setting up wireshark to look theres a video available Wireshark Introduction

Posted
Ethereal is another...

Ethereal is what Wireshark used to be called before they changed the name. I'm surprised the site is even still there, but although it hasn't been updated in years, the SourceForge download links take you to the Wireshark project page.

Posted
Hi

 

ok thanks i will try this out tomorrow. i have seen this being used before but im not quite sure how to set up the capture??:confused:

 

yeah there is an isa server but its more used for checking people coming in through to our web mail server, can i still use it to track this down then??

 

I suggest you have a quick read through the FAQs / Instructions - capture a 10 second blast on a segment of your network where you know you are getting problems - then post the data [ zip it up as it will be quite large ] and let a few people look at the data - you may get a few conflicting results from people but I am sure one or two of us will agree.....

Posted
Ethereal is what Wireshark used to be called before they changed the name. I'm surprised the site is even still there, but although it hasn't been updated in years, the SourceForge download links take you to the Wireshark project page.

 

Fair enough, just proves how old I am when it comes to using certain applications !!!

Posted
also check your anti-virus server as it may have picked things up that you don't want - but hasn't installed properly on the machine that is sending the packets - also check domain controllers for mass failed login attempts
Posted
If you have ISA 2006, as long as you have ISA Server 2006 Supportability Update (KB939455) applied to your ISA server you can use the Log Viewer (Logging tab in Monitoring) to filter and view all traffic in the logs - doesn't have to be live data: just change the Log Time from "Live" to whatever interval you want to examine.
Posted
Ethereal is what Wireshark used to be called before they changed the name. I'm surprised the site is even still there, but although it hasn't been updated in years, the SourceForge download links take you to the Wireshark project page.

 

mattx - say hello to the future , future say hello to mattx - as above its now wire shark which as angrytech stated above.

Posted

just a quick one this is the reports that our isp is giving us

 

Inuse Entries: 43 Perm Entries: 0

Pending Entries: 0

Out Request: 14 Out Response: 0

In Request: 156 In Response: 14

Proxy Answered: 0

Rx Error: 0 Dup IP Addr: 0

Rejected count: 5 Rejected IP: 127.0.0.1

Rejected Port: 2 Rejected I/F: bnt-mhh-cu

Posted
just done my first capture but cant make head nor tail of it i have attached the file can any one make sense of this??

 

I couldn't read it, what did you save it as?

Posted

prolly a daft thought so appologies in advance to the OP and everyone else

 

You haven't setup or configured a web server anywhere have you ie IIS or apache ??

 

That or a duff / dead network card ??

Posted (edited)

Just had a quick look..... Lots of ARP requests......

Also frame 178 has me a little confused. Is that a switch looking for 127.0.0.1 ? As it's pointing to another switch which states it's the same address ? It's as if they are fighting it out between themselves.

Also Sophos is looking for something on a different subnet !!

Edited by mattx
Posted (edited)
Need someone else to back me up but I would look at the configs of the two switches - Netgear ? [ if they are switches ] of frames 178 & 160 - [ the mac addresses are in the capture file ] Edited by mattx
Posted

hi i missed that when i looked at it the first time round. nice one i have looked at it again and tracked the device it is a WAP. i went and killed the wap and the switch that its connected to i then run a second scan [ the one attached] i then checked through the logs and noticed it appearing on the next wap in the area and the one next to that and the one next to that...and theone next to that!

 

they are on frames 96,99,126,137

 

do you think i may have a rogue wireless device or outside device???

second.zip

Posted (edited)

do you wap have a controller? or are they unmanaged?

 

Edit: what has the addresses that 127.0.0.1 is trying to look up?

 

for the second round its

10.11.71.103

10.11.71.116

10.11.71.107

10.11.71.114

Edited by glennda
Posted
Hi thanks for all the replies i have sorted this out now. it seems that aload of the waps have reset and the firm ware has been trashed so im now in the process of redoing all of them.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...