Karlnet
[Top] [All Lists]

[Karlnet] Ping Floods, DoS Attacks, etc. - Any Ideas

To: "Karlnet Mailing List" <karlnet@wispnotes.com>, <RMallory@karlnet.com>
Subject: [Karlnet] Ping Floods, DoS Attacks, etc. - Any Ideas
From: "Brett Hays" <bretth@htonline.net>
Reply-to: Brett Hays <bretth@htonline.net>, Karlnet Mailing List<karlnet@WISPNotes.com>
Date: Tue, 17 Jun 2003 09:24:37 -0500
List-post: <mailto:karlnet@WISPNotes.com>
We have finally isolated a problem we have been having for over a month on
our wireless system with some customers falling offline, etc on mostly
nights and weekends for 5-15 minute durations due to excessive icmp (I
believe) traffic coming from one customer location.  The customer is working
with us to isolate the offending machine/device and solve the problem.

That said, this has been a mother to isolate and solve.  Does anyone have
any ideas on how to protect access points from one client with code red,
etc. pegging the whole network?  We run AP1000 base and RG1100 clients.
Currently, we are routed with real world IP's on the RG's and nat for the
customer on the ethernet side.  I noticed in the bridging setup that there
is a section called storm protection.  If we were running bridging on the
clients and had this enabled, would it protect from this sort of problem?

I know that some of you have said you run nat on the access point and then
give the real world IP to the customer's computer or dsl/cable router.  My
question regarding this is how do you access the client devices (in our case
RG's) to change configuration, etc. if they are behind nat on the access
point?

Please excuse any stupid questions I am asking, I have very limited
experience with bridging.

Brett Hays
Hometown Online
www.htonline.net


<Prev in Thread] Current Thread [Next in Thread>