LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Security (https://www.linuxquestions.org/questions/linux-security-4/)
-   -   Broadcast to unknown IP addresses (https://www.linuxquestions.org/questions/linux-security-4/broadcast-to-unknown-ip-addresses-745263/)

sabir_mustafa 08-05-2009 06:56 AM

Broadcast to unknown IP addresses
 
Dear all:
Recently i have deployed squirrel mail 1.4 on a RHEL5 box at client internal network. Every thing is running fine but one of my ip tools has detected e numerous broad cast to different IP addresses like 192.x.x.x or 151.x.x.x or 153.x.x.x.
I am not much worried since the company is using this email service inside their internal perimeter, but i want to know what exactly is going on. Does I need to configure iptables to block such broad cast?

Thanks

TB0ne 08-05-2009 11:21 AM

Quote:

Originally Posted by sabir_mustafa (Post 3632134)
Dear all:
Recently i have deployed squirrel mail 1.4 on a RHEL5 box at client internal network. Every thing is running fine but one of my ip tools has detected e numerous broad cast to different IP addresses like 192.x.x.x or 151.x.x.x or 153.x.x.x.
I am not much worried since the company is using this email service inside their internal perimeter, but i want to know what exactly is going on. Does I need to configure iptables to block such broad cast?

Thanks

Hard to say...you don't say what "ip tool" is returning this information, in what circumstance, or give any details about your network. Since we don't know what IP ranges you use internally, what the exact output of the "ip tools" is, it's hard to say if it's normal or not.

sabir_mustafa 08-07-2009 12:30 AM

Dear all:
I have carefully reviewed the network. The tools I m using are "wire shark" and "com view". The broad cast that I have recorded is from my mail server to external IP addresses, I already mentioned. Now i can't understand why is this happening.

nowonmai 08-07-2009 03:44 AM

What else does wireshark say about the packets? It should give enough detail to determine what's going on.

unixfool 08-07-2009 05:16 PM

Posting some of the packets to the forum may help us understand what the issue may be. If you post some, sanitize any crucial data you may not want to be showing to the public.

sabir_mustafa 08-08-2009 06:47 AM

I shall post the packet on monday. As today i m on rest from company.

sabir_mustafa 08-11-2009 07:53 AM

Quote:

Originally Posted by unixfool (Post 3635200)
Posting some of the packets to the forum may help us understand what the issue may be. If you post some, sanitize any crucial data you may not want to be showing to the public.

I have checked all the data in wireshark. It is an ARP broad cast from mail server IP address and MAC to the x.x.x.x IP address and all 00:00 MAC. Is it OK.

sabir_mustafa 08-26-2009 10:26 PM

Well: I got control of it. I used IPTABLES to block broad cast from mail server to any other network except specified trusted networks, further binding a custom https port through which clients can access the server.


All times are GMT -5. The time now is 05:07 AM.