Re: blocking incoming udp packets
- From: comphelp@xxxxxxxxx (Todd H.)
- Date: Wed, 09 Jul 2008 13:06:15 -0500
JClark <jclark@xxxxxxxxxxxxxx> writes:
Returning to the original question, a summary, as I see it (not
necessarily correctly):
It seems the router is sending udp packets to 255.255.255.255 (both
source and destination ports = 520, or to 192.168.1.255 (source port
ranging from 7000 to 7259, and destination port 162.
I have no idea what this all means.
UDP 162 is the SNMP trap port. If you're not familiar with simple
network management protocol, this traffic to 162 may simply be the
network device attempting to send traps to be logged by an SNMP
management station.
UDP 520 is RIP routing. The router is advertising routes with this
exceedingly simple, easy to spoof protocol.
Both should be functionality that can be disabled in the source
network device.
Best Regards,
--
Todd H.
http://www.toddh.net/
.
- Follow-Ups:
- Re: blocking incoming udp packets
- From: JClark
- Re: blocking incoming udp packets
- From: JClark
- Re: blocking incoming udp packets
- References:
- blocking incoming udp packets
- From: JClark
- Re: blocking incoming udp packets
- From: VanguardLH
- Re: blocking incoming udp packets
- From: JClark
- Re: blocking incoming udp packets
- From: VanguardLH
- Re: blocking incoming udp packets
- From: JClark
- blocking incoming udp packets
- Prev by Date: Re: Double Encryption!!!
- Next by Date: Re: Double Encryption!!!
- Previous by thread: Re: blocking incoming udp packets
- Next by thread: Re: blocking incoming udp packets
- Index(es):
Relevant Pages
|