Re: Neighbor table overflow. Virus?



On 24 Jan 2006, in the Usenet newsgroup comp.os.linux.networking, in article
<1138093069.792509.323560@xxxxxxxxxxxxxxxxxxxxxxxxxxxx>, nsa.usa@xxxxxxxxx
wrote:

>Sorry if I didn't make that clear. As soon as I disconnect that client
>the problem disappears in the server. It is obvious from the ARP table
>that hundreds of connections are comming from this client that cannot
>be established.

Entries in the ARP tables should only occur for IP addresses that are
local to this computer. Looking at your routing table should show what
the O/S deems to be local. Are you using some unusual netmasks?

>The client is running a windows version by the way.

In theory, sniffing the connection to see WTF it's trying to connect
to might help, as the dialin box isn't using ARP (a ppp connection does
not). This means you can see what address, port, and protocol is trying
to be used.

Old guy
.



Relevant Pages

  • SUMMARY: Prevent Solaris from broadcasting ARP for second interface over first interface.
    ... What I have done already is disable ARP on the interface and create ... The private x-cover connection uses addresses in the ... > We often see when server B x-over sends and ARP for 10.10.210.21, ...
    (SunManagers)
  • Re: another jumpstart issue.
    ... Looks very much like unresolved direct ARP broadcasts. ... Snoop on the server to see what exactly does the client broadcast for. ... Post bootparams, ethers and hosts files here, ...
    (comp.unix.solaris)
  • Re: Advanced Security Question
    ... > 192.168.100.100 and then use the real mac address of that client when it ... but in the latter case the same arp table should be ... Use two NICs on the ...
    (comp.os.linux.security)
  • Re: NIM over WAN
    ... JA> I've been trying to use NIM with AIX 4.3.3 and AIX 5.1 over a WAN, ... the client locks up with an 'arp error' message (can't recall ... NIM works just fine when I use it in the same ... JA> cities, I get arp problems. ...
    (comp.unix.aix)
  • Re: ARP
    ... "server" when it "serves" something to something else. ... > no client on this server which would need ARP resolution in whole LAT ... You could have a network with nothing but Routers and Switches and not one ...
    (microsoft.public.isa)