Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Jeffrey Laramie <JALaramie@Loudoun-Fairfax.com>
To: Ramin Dousti <ramin@cannon.eng.us.uu.net>
Cc: netfilter@lists.netfilter.org
Subject: Re: External IP addresses on internal network
Date: Thu, 28 Aug 2003 15:24:48 -0400	[thread overview]
Message-ID: <3F4E5700.8030700@Loudoun-Fairfax.com> (raw)
In-Reply-To: <20030828181717.GA3993@cannon.eng.us.uu.net>

Hey all,

You guys must hate me by now. I've had a handful of good responses and 
been responding and cc'ing the list trying to keep everyone current, but 
with the list lag it isn't working very well. If your box isn't full 
yet, it will be. Sorry.

Ramin Dousti wrote:

>On Thu, Aug 28, 2003 at 12:05:24PM -0400, Jeffrey Laramie wrote:
>  
>
>>>Could it be that the client machine dials up to AOL, receives that IP
>>>address and later it needs to resolve a name and vecause of the DNS
>>>settings on the client machine it tries the query 192.168.0.24 with
>>>its source 172.144.233.136?
>>>
>>>      
>>>
>>Thanks for the suggestion. That was my first thought since one of the LAN
>>clients is a notebook with dialup ability, but with a DSL connection through
>>the LAN it's not used now. I did check it though to see if it still had an
>>AOL IP assigned to it or an AOL server listed for DNS. It didn't, and the log
>>timestamp indicates that these packets are occuring when a different client
>>(with no dialup) is checking AOL mail.
>>
>>    
>>
>
>What about this theory (although I don't know anything about the AOL stuff)
>that the client connects to AOL. AOL sets up a tunnel with this client
>and assigns 172.144.233.136 to it. Then due to the static DNS settings
>on the client, a DNS query is made to your named on the firewall, instead
>of using AOL's DNS server?
>
I don't know much about tunneling, but this sounds possible. Almost like 
a remote shell where the server session runs on client hardware, except 
here the DNS call gets mis-handled and sent to the client nameserver 
instead?

Chris had a very good theory too:  (quoted here in case you didn't get 
it yet)

> This obviously is not a legit DNS request because the source port is 
> wrong (should be 53 or >1023). My guess is a brain dead Windoze system 
> or even more likely, a load balancer.
>
>> The firewall host is also a DNS server for my LAN so this would be a 
>> normal request coming from the LAN **except** for the client IP address.
>
>
> I've seen this before. An internal client goes to access a Web site 
> (say www.fubar.org) and the authoritative NS is actually a load 
> balancer. It spews suspicious looking traffic at the requesting NS in 
> order to generate performance metrics to figure out what IP to serve 
> back (assumption being the client is close to the NS).
>
> So if this is the case, you should see a query for a host within the 
> AOL domain (owner of the address space) just prior to this traffic.

This is good stuff, thanks guys. I'll let you know if I find out 
anything definative.

Jeff



  reply	other threads:[~2003-08-28 19:24 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-08-26 22:43 External IP addresses on internal network George Vieira
2003-08-27  1:10 ` Jeffrey Laramie
2003-08-27 16:54   ` Jim Carter
2003-08-27 18:50     ` Jeffrey Laramie
2003-08-28 14:19       ` Chris Brenton
2003-08-28 15:43         ` Jeffrey Laramie
2003-08-28 14:56       ` Ramin Dousti
2003-08-28 16:21         ` Jeffrey Laramie
     [not found]         ` <3F4E2844.2050108@Loudoun-Fairfax.com>
2003-08-28 18:17           ` Ramin Dousti
2003-08-28 19:24             ` Jeffrey Laramie [this message]
2003-08-28 15:52       ` Michael J. Tubby B.Sc. (Hons) G8TIC
2003-08-28 16:19         ` Jeffrey Laramie
  -- strict thread matches above, loose matches on Subject: below --
2003-08-26 15:57 Jeffrey Laramie

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=3F4E5700.8030700@Loudoun-Fairfax.com \
    --to=jalaramie@loudoun-fairfax.com \
    --cc=netfilter@lists.netfilter.org \
    --cc=ramin@cannon.eng.us.uu.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox