Re: Ping of Dead on LAN

From: Roger A. Grimes (rogerg_at_cox.net)
Date: 07/15/03

  • Next message: Birl: "Re: AW: Multi-User Access to Password Database"
    To: <nathan.grandbois@cerdant.com>, "'Darren Gragg'" <admin@bsbks.com>, <security-basics@securityfocus.com>
    Date: Tue, 15 Jul 2003 12:49:17 -0400
    
    

    You can turn on and off accepting packet fragmentation in Sonicwall's GUI.
    I believe it's turned off by default.

    I'm a little skeptical that this is a MTU problem, but I'm skeptical that
    I'm intelligent enough to participate in this conversation at all. <grin>

    Darren can test this theory by modifying XP's registry to turn off MTU
    fragmentation.

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interf
    aces\ID for AdapterTcpip\Parameters\EnablePMTUDiscovery
    Set it to zero vs. the default of 1, reboot and see if turning off large MTU
    sizes fixes the problem.

    Also, Darren can use Sonicwall's packet capturing ability to see if
    fragmentation flags are set on the packets causing the problem.

    Roger
    ****************************************************************************
    ****
    *Roger A. Grimes, Computer Security Consultant
    *CPA, MCSE (NT/2000), CNE (3/4), A+
    *email: rogerg@cox.net
    *cell: 757-615-3355
    *Author of Malicious Mobile Code: Virus Protection for Windows by O'Reilly
    *http://www.oreilly.com/catalog/malmobcode
    *Author of upcoming Honeypots for Windows (Apress)
    ****************************************************************************
    *****

    ----- Original Message -----
    From: "Nathan" <nathan.grandbois@cerdant.com>
    To: "'Roger A. Grimes'" <rogerg@cox.net>; "'Darren Gragg'"
    <admin@bsbks.com>; <security-basics@securityfocus.com>
    Sent: Tuesday, July 15, 2003 9:13 AM
    Subject: RE: Ping of Dead on LAN

    > I've seen this myself on a Pro300. It is an issue in the sonicwall where
    > they are over protective. Every time a fragmented packet crosses the
    > sonicwall it logs it as a ping of death and drops it (I assume it drops
    it).
    > I've talked to our regional sonicwall engineer and they said it is
    something
    > they know about and are working on. You can set the Path MTU on your
    windows
    > machine to be lower, try like 1440, to prevent packet fragmentation. You
    > might also try messing with the MTU on the SonicWall, but I don't think
    that
    > is where the problem is. Your right about the XP thing, as the customer we
    > manage only has this problem with IP's associated with XP machines. It's
    > something to do with XP fragmenting packets.
    >
    > -Nathan

    ---------------------------------------------------------------------------
    Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts!
    The Gartner Group just put Neoteris in the top of its Magic Quadrant,
    while InStat has confirmed Neoteris as the leader in marketshare.
         
    Find out why, and see how you can get plug-n-play secure remote access in
    about an hour, with no client, server changes, or ongoing maintenance.
              
    Visit us at: http://www.neoteris.com/promos/sf-6-9.htm
    ----------------------------------------------------------------------------


  • Next message: Birl: "Re: AW: Multi-User Access to Password Database"

    Relevant Pages

    • Re: [Lhms-devel] [PATCH 0/7] Fragmentation Avoidance V19
      ... sufferd from fragmentation when MTU is big. ... gathering fragmented skbs.When these skb_* funcs failed, the packet ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: Not able to establish trust with another window 2003 domain
      ... Not the "Packet needs to be fragmented but DF set". ... I try to use my target domain to create a trust to one of my ... establish a trust to my source, its fail. ... I also though about UDP fragmentation, do you see any kerberos errors on ...
      (microsoft.public.windows.server.active_directory)
    • Re: MSS on router, why?
      ... The proper way to describe the ICMP packet which is supposed to be ... returned by a router which cannot forward the IP packet which is too ... Because ICMP was defined before Path MTU Discovery (1981 and 1990 ... fragmentation and try to use path MTU discovery, ...
      (comp.dcom.sys.cisco)
    • Re: Userspace packet queuing with libipq: ip_conntrack does not defragment?
      ... IP packet - usually with a size of around 10 KB. ... according to the MTU size in order to avoid IP ... Indeed this is what I would expect to see, unless the path MTU is lower than the interface MTU and the hosts do not use path MTU discovery, thus causing fragmentation on some router along the path. ...
      (comp.os.linux.networking)
    • Re: PPTPd + pptp-client / Linux Net-2-Net VPN / Slow connection
      ... > it would be strange, but it might be an MTU issue, but where you have packet ... See what happens if you force your MTU to ... > fragmentation. ... Please note that my problem with the low bandwidth seems to be fixed. ...
      (comp.os.linux.networking)