site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
835
Share Topic
Posting?
Post a:
Post a:
Links: ·Submit a new forum topic ·Forum FAQ ·Submit a FAQ ·Docs Guidelines and Advisories ·EOS/EOL thread
AuthorAll Replies

JDmailNY

join:2007-12-02
Pearl River, NY

[HELP] Virus could be attaching router

I have a Cisco 2600 series router with a T1 wan connection to Verizon. Recently our wan connection for the past three days bounces and the WAN light turns red. The provider is having alot of problems finding out whats wrong. Could this be a virus ??.
Which type of sniffer can I use, besides wireshark.

HELLFIRE

join:2009-11-25
kudos:4

Never heard of a virus that 'bounces' a WAN connection before. Where does
the light go red, the WIC card or an external xSU unit? Do you have any
sort of logging software monitoring the router, and if so what do they show?
What about the output of 'show controllers t1'?

If it's a circuit hard down issue, that's a L1 / L2 problem and wireshark,
et al isn't going to tell you much. Wireshark is my preferred tool for
Windows, but there's TCPdump for *nix.

And really dumb question, what has the provider done in terms of troubleshooting
or problem isolation. I get really sick on providers who give the generic
'we checked and found nothing' spiel. Did they do remote testing and where?
Did they do intrusive / stress-testing on the circuit and with what patterns?
Did they only do 1 type of pattern testing, or multiple, and how long? If this
is production impacting, I'd get them to schedule a head-to-head test where
you basically loop between their CO router and yours for a couple hours.

Just my 00000010 bits.

Regards



phantasm11b
Premium
join:2007-11-02

What Hellfire said. A virus won't affect your WAN interface on your router. If your WAN circuit is bouncing or taking errors then you should see the problem indicated on your WAN interface.

Log into the router and do a show interface . Look for input errors, carrier transition, aborts and whatever else is present. You can also clear the counters on that interface to get a fresh bench mark then check it periodically.

Either way VZ needs to perform an intrusive test on the ckt to identify any issues.
--
"There are two American flags flying on the property I reside on. Anyone who tries to take them down will be rendered inoperative." -Lindy



Jameson
Premium
join:2004-05-28
Fallbrook, CA
kudos:1

Also check to make sure that you're not having packet collisions (aka duplex).


JDmailNY

join:2007-12-02
Pearl River, NY

I just found out from Verizon, they did see packet dicards on there end, they rebuilt the private virtual circuit and it appears to be working again.


Network Guy
Premium
join:2000-08-25
New York

Probably spoke to a tech support guy from India at first.



RFP
Aerie Gang of Eagles

join:2003-12-29
Hollis, NY

1 edit

"Network Guy" for 10 years on dslr you sure have basic common sense. Does it matter if the guy's from India or not? Have you ever talked to Cisco TAC in your life?

There are bots aka "VIRUSES" out there built specifically for harvesting/ Rooting Routers and Switches. Google it.

Secure your Router and overall network.

Simple google search for securing your Routers, many more can be found.

»www.infosecwriters.com/text_reso···isco.pdf


Network Guy
Premium
join:2000-08-25
New York
Reviews:
·Optimum Online
·Verizon Online DSL

It was merely a wise ass comment.

With proper ACLs in place no one should have to worry about things like rooting of a router or harvesting. One of my rules of thumb.. If a network admin wants the convenience of managing border devices remotely, good countermeasures take higher priority over access.



TomS_
Git-r-done
Premium,MVM
join:2002-07-19
Ireland
kudos:1

If they want remote access, then they VPN in and access it from the "inside".

Inside out, not outside in.

Me personally, I use ACLs to lock down access to the VTY lines of my devices to a few select internal hosts. Of those hosts, only one is actually accessible from outside the network, and only via SSH.



phantasm11b
Premium
join:2007-11-02

said by TomS_:

If they want remote access, then they VPN in and access it from the "inside".

Inside out, not outside in.

Me personally, I use ACLs to lock down access to the VTY lines of my devices to a few select internal hosts. Of those hosts, only one is actually accessible from outside the network, and only via SSH.
This is my preferred method as well.
--
"There are two American flags flying on the property I reside on. Anyone who tries to take them down will be rendered inoperative." -Lindy

Friday, 01-Jun 21:52:13 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics