Re: [fw-wiz] How to find hidden host within LAN



On Nov 25, 2007 6:42 AM, desant1@xxxxxx <desant1@xxxxxx> wrote:
Hi everybody
I'm using RH ES4 with iptables as gateway/firewall for my
LAN.
In the last week i notice in the iptables logs that a host within
my lan is doing a lot of traffic.
The destination/source address of the
packets and the used port suggest that this host is using peerToPeer
application (emule or similar).
The problem is that i'm not able to
identify this host within my LAN:
I can see his IP address (192.168.x.
y) and i can find his mac address througth ARP, but i can't ping it and
there is no host within my lan with this Mac address.
I can't
traceroute it.
Can someone help me to find this hidden host?

Are your switches managed? Can you pin down the MAC address to a switch port?

Is it coming over a wireless connection? If so, can you simply deny
that MAC address and see who complains?

Does that IP address do *anything* else on your LAN, and do you log
other activity, or can you put a network capture utility
(wireshark/tcpdump/other) to record anything else that this host is
talking to? if so you should be able to note and correlate login
activity with IP address.
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: how to find hidden host within LAN
    ... securing wireless so some users in the adjacent office were using his ... goto each pc on your lan.. ... It will list the Mac Address of the PC. ... You can block the host using too much traffic with iptables.. ...
    (RedHat)
  • Re: ICS questions and confusion
    ... >>> has to be another subnet altogether. ... WHY does the LAN connection that connects my router to the ... >>host have to be on a different subnet than the 192.168.0.x one? ... >>where is that documented in all the how-to's on ICS, ...
    (microsoft.public.windowsxp.network_web)
  • Re: [fw-wiz] How to find hidden host within LAN
    ... Is the IP address within a valid range on your network or are we talking ... You can completely block that host from Internet access in IPTables by using ... Depending on your LAN setup you may be able to check your mac tables on your ...
    (Firewall-Wizards)
  • Re: [fw-wiz] How to find hidden host within LAN
    ... there is no host within my lan with this Mac address. ... Tho you said it doesn't ping, ...
    (Firewall-Wizards)
  • Re: router causing ssh etc. slowdown?
    ... >> port on their public IP from a host on their own LAN. ... Let's say host A starts a TCP connection from its ... The router sends the SYN packet to ...
    (Fedora)