New Zealand ADSL Mailing List


RE: ADSL routers with DHCP spoofing? Anyone?

From: Neil Gardner <neil_at_neilnz.com>
Date: Sat, 18 Oct 2003 21:41:11 +1300
Message-ID: <000001c39553$957f06a0$6663a8c0@delta>

In response to my own email a while ago on this topic I have a few more
questions.. (and a couple of findings)

1) The DSE XH1149 and Speedtouch Pro both do DHCP spoofing and both work
fine with Windows XP as the DHCP client... Interestingly, although
IPCONFIG shows them as having a public IP with a gateway of the public
IP of the DSL gateway, a tracert shows the private interface (and IP) of
the ADSL routers as the first hop... This is I believe contributing to
my problem below...

2) I have a problem when using at least the Speedtouch Pro (haven't
tried the DSE model yet) along with a Netscreen 5GT firewall. It gets
assigned the public IP just fine, and when I try to ping from the 5GT,
it work ONLY for the gateway address (203.x.x.x) at about 40ms which is
obviously remote.

All other addresses fail and the debug mode of the firewall indicates
that the packets are getting out successfully, but that the strangeness
of the 'transparent' bridging from WAN port on the Pro to the untrust on
the 5GT appears to break it.

I could reconfigure and get the debug output from the packets but
unfortunately someone else here (at my flat) demanded a working internet
connection.

If there's anyone here that could decipher the debug flow output from
the Netscreen 5GT please put your hand up. I'm fresh off a NS training
course and thought I had a pretty good handle, but the debug output is
quite different than I would expect.

Cheers - Neil G

-- 
This message is part of the NZ ADSL mailing list. 
see http://unixathome.org/adsl/ for archives, FAQ, 
and various documents. 
To unsubscribe: send mail to majordomo@lists.unixathome.org 
with "unsubscribe adsl" in the body of the message 
 
Received on Sat Oct 18 21:41:27 2003

This archive was generated by hypermail 2.2.0 : Thu Nov 30 11:48:26 2006 EST