RE: Strange SNMP probes suddenly appearing

From: Graeme Fowler (graeme.fowler_at_hosteurope.com)
Date: 12/11/03

  • Next message: Harlan Carvey: "Re: Strange services.exe file"
    Date: Thu, 11 Dec 2003 13:59:58 -0000
    To: "Jeff Kell" <jeff-kell@utc.edu>
    
    

    Hi

    On 03 December 2003 02:23, Jeff Kell wrote:
    > After finally getting an ethereal trace of traffic from the faulty
    > address (a machine using an Apple Airport) I found the following:
    <snip>
    > Almost immediately afterward is a UDP packet from that machine to the
    > router on port udp/192. It contains 4 bytes of text, 0x08 0x01 0x03
    > 0x10.
    <snip>
    > So, "something" is amiss here. I'm just not sure I understand it all.
    > But we have the symptoms nailed down, we'll have to see about the
    > cure. Does this ring any bells with anyone that is AirPort
    > knowledgeable? Since these were "rogue installs" by the department,
    > they look like they would be great clay pigeons for skeet shooting,
    > but perhaps they can be more productive.

    A quick scout of Apple's tech info library gave up the following
    documents:

    http://docs.info.apple.com/article.html?artnum=106439
    "This document lists TCP and UDP ports used by Apple software products
    <snip>
    UDP Port Service
    192 AirPort Base Station PPP status or discovery (certain
    configurations)"

    Interesting. So the Airport Base Station can toddle off and do some sort
    of discovery - in my experience (with other discovery devices), it'll
    start with its' default router to see what it can find and will then
    poll the local LAN, or followup anything interesting it might find via
    the initial probe. Presumably, in these cases, the AirPort base station
    is configured to get an IP address via DHCP and then do local NAT for
    wireless devices which connect through it.

    http://docs.info.apple.com/article.html?artnum=107220
    Decribes how to turn off SNMP on the "WAN" port of a dual ethernet base
    station. I'd surmise that the use of the word "WAN" here means "Wired
    LAN" :)

    ...and then I go a-googling, and find:

    http://sourceforge.net/docman/display_doc.php?docid=12&group_id=7489
    describing the discovery modes of the base station itself using port
    192.

    Having read around the subject over the last half hour or so, I'd say
    that the base stations in their default, plug'n'go state, are trying to
    discover a management station from which they can download their
    configuration. The AirPort management software does its' magic via SNMP
    (so it seems!) so it wouldn't surprise me, with Apple's move towards
    automagic configuration of desktops and servers from the OSX Server
    environment, that this is not nefarious activity - it's by design, and
    (like many other scenarios) it's default behaviour which should be
    switched off before plugging the devices into a LAN.

    Hope that helps, at least a little.

    Regards

    Graeme Fowler

    --
    Technical Services
    Host Europe PLC
    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------
    

  • Next message: Harlan Carvey: "Re: Strange services.exe file"

    Relevant Pages

    • Re: AirportExtreme question.
      ... will this station support DSL modem? ... You will have a WAN port for connecting to the DSL ... and saw an extra power adapter for base station; ... Airport Extreme is just Apple's name for 802.11g WiFi. ...
      (comp.sys.mac.hardware.misc)
    • Re: router recommendation?
      ... The iMac doesn't have an Airport card though I might add one at some point. ... If the receipt is dated 2000, the base station cannot be an "Airport ... There was a Dual Ethernet model, white in colour, from November ... Express doesn't offer a modem; I guess they dropped that at some point. ...
      (comp.sys.mac.comm)
    • Re: router recommendation?
      ... The iMac doesn't have an Airport card though I might add one at some point. ... If the receipt is dated 2000, the base station cannot be an "Airport ... There was a Dual Ethernet model, white in colour, from November ... Express doesn't offer a modem; I guess they dropped that at some point. ...
      (comp.sys.mac.comm)
    • Re: Quick Airport Express question
      ... My lads PC and my powerbook have poor connectivity upstairs to my ... Wireless network - Airport Extreme which is down in the kitchen. ... repeating the signal via another base station will ...
      (uk.comp.sys.mac)
    • Re: Mixing Airport (11mbps) and Airport Extreme (54mbps)
      ... The transmitter sent 8192 1024 byte blocks and closed the connection. ... The receiving computer was a 700 MHz G3 iMac connected to an AirPort ... Extreme base station via 100 Mb ethernet. ... enabled but idle. ...
      (comp.sys.mac.system)