I too am getting this and have been for a few weeks now but initiated by a different address...
07:04:00.406011 IP 209.189.196.68 > 192.168.1.150: IP 0.0.0.0.5678 > 255.255.255.255.5678: UDP, length 119 (ipip-proto-4) 07:05:00.408246 IP 209.189.196.68 > 192.168.1.150: IP 0.0.0.0.5678 > 255.255.255.255.5678: UDP, length 119 (ipip-proto-4)
73, Don
On Thu, Jan 30, 2014 at 12:49 AM, Jerome Schatten romers@shaw.ca wrote:
44ers...
So every minute of every hour of every day, I get this below; it started several weeks ago. It looks like it's coming from the Ampr portal -- why? 24.84.205.232 is indeed my ip and it seems that 209.84.205.232 is the same ip as the rip broadcasts are coming from. Is there any way to turn this off other than turning off rip?
Wed Jan 29 21:35:27 2014 - tun0 recv: IP: len 167 209.189.196.68->192.168.1.149 ihl 20 ttl 55 DF prot IP IP: len 147 0.0.0.0->255.255.255.255 ihl 20 ttl 64 prot UDP UDP: len 127 5678->5678 Data 119 0000 ..1.....Seattle-ER1....6.7....MikroTik............FLNH-GLS0....R 0040 B2011UAS......................T......ampr-24.84.205.232 (encap) 0.0.0.0->255.255.255.255 UDP 0000 ..1.....Seattle-ER1....6.7....MikroTik............FLNH-GLS0....R 0040 B2011UAS......................T......ampr-24.84.205.232
jerome - ve7ass
nos-bbs mailing list nos-bbs@tapr.org http://www.tapr.org/mailman/listinfo/nos-bbs
I have those packets, too. These ports are used by MikroTik Neighbor Discovery Protocol (MNDP)
http://www.mikrotik.com/documentation/manual_2.7/IP/MNDP.html
The operator of 209.189.196.68 probably enabled it on all interfaces, including ampr tunnels.
AFAIK the source of the RIP broadcasts should be 169.228.66.251 (just checked it now).
Marius, YO2LOJ
-----Original Message----- From: 44net-bounces+marius=yo2loj.ro@hamradio.ucsd.edu [mailto:44net-bounces+marius=yo2loj.ro@hamradio.ucsd.edu] On Behalf Of Don Moore Sent: Thursday, January 30, 2014 14:10 To: TAPR xNOS Mailing List; AMPRNet working group Subject: Re: [44net] [nos-bbs] strange udp broadcasts...
(Please trim inclusions from previous messages) _______________________________________________ I too am getting this and have been for a few weeks now but initiated by a different address...
07:04:00.406011 IP 209.189.196.68 > 192.168.1.150: IP 0.0.0.0.5678 > 255.255.255.255.5678: UDP, length 119 (ipip-proto-4) 07:05:00.408246 IP 209.189.196.68 > 192.168.1.150: IP 0.0.0.0.5678 > 255.255.255.255.5678: UDP, length 119 (ipip-proto-4)
73, Don
On Thu, Jan 30, 2014 at 12:49 AM, Jerome Schatten romers@shaw.ca wrote:
44ers...
So every minute of every hour of every day, I get this below; it started several weeks ago. It looks like it's coming from the Ampr portal -- why? 24.84.205.232 is indeed my ip and it seems that 209.84.205.232 is the same ip as the rip broadcasts are coming from. Is there any way to turn this off other than turning off rip?
Wed Jan 29 21:35:27 2014 - tun0 recv: IP: len 167 209.189.196.68->192.168.1.149 ihl 20 ttl 55 DF prot IP IP: len 147 0.0.0.0->255.255.255.255 ihl 20 ttl 64 prot UDP UDP: len 127 5678->5678 Data 119 0000 ..1.....Seattle-ER1....6.7....MikroTik............FLNH-GLS0....R 0040 B2011UAS......................T......ampr-24.84.205.232 (encap) 0.0.0.0->255.255.255.255 UDP 0000 ..1.....Seattle-ER1....6.7....MikroTik............FLNH-GLS0....R 0040 B2011UAS......................T......ampr-24.84.205.232
jerome - ve7ass
nos-bbs mailing list nos-bbs@tapr.org http://www.tapr.org/mailman/listinfo/nos-bbs
On Thu, Jan 30, 2014 at 06:26:37PM +0200, Marius Petrescu wrote:
The operator of 209.189.196.68 probably enabled it on all interfaces, including ampr tunnels.
That host resolves to WESTIN-ER1.HAMWAN.ORG so it's quite possible that the operator is a subscriber to this mailing list and can correct the problem now that they know about it. Please. - Brian
I'll try to get ahold of Bart, their Wiki is down at the moment.
http://www.youtube.com/watch?v=Vhj9bS8n9jM -- start Minute 7:30
------------------------------ John D. Hays K7VE PO Box 1223, Edmonds, WA 98020-1223 http://k7ve.org/blog http://twitter.com/#!/john_hays http://www.facebook.com/john.d.hays
On Thu, Jan 30, 2014 at 8:29 AM, Brian Kantor Brian@ucsd.edu wrote:
(Please trim inclusions from previous messages) _______________________________________________ On Thu, Jan 30, 2014 at 06:26:37PM +0200, Marius Petrescu wrote:
The operator of 209.189.196.68 probably enabled it on all interfaces, including ampr tunnels.
That host resolves to WESTIN-ER1.HAMWAN.ORG so it's quite possible that the operator is a subscriber to this mailing list and can correct the problem now that they know about it. Please. - Brian _________________________________________ 44Net mailing list 44Net@hamradio.ucsd.edu http://hamradio.ucsd.edu/mailman/listinfo/44net
Heard from Bart, their network team is on it.
------------------------------ John D. Hays K7VE PO Box 1223, Edmonds, WA 98020-1223 http://k7ve.org/blog http://twitter.com/#!/john_hays http://www.facebook.com/john.d.hays
On Thu, Jan 30, 2014 at 8:29 AM, Brian Kantor Brian@ucsd.edu wrote:
(Please trim inclusions from previous messages) _______________________________________________ On Thu, Jan 30, 2014 at 06:26:37PM +0200, Marius Petrescu wrote:
The operator of 209.189.196.68 probably enabled it on all interfaces, including ampr tunnels.
That host resolves to WESTIN-ER1.HAMWAN.ORG so it's quite possible that the operator is a subscriber to this mailing list and can correct the problem now that they know about it. Please. - Brian _________________________________________ 44Net mailing list 44Net@hamradio.ucsd.edu http://hamradio.ucsd.edu/mailman/listinfo/44net
Don, This is mikrotik discovery protocol. I'll talk to the device owner to see if we can turn that off.
Tim Osburn www.osburn.com W7RSZ
On Thu, 30 Jan 2014, Don Moore wrote:
Date: Thu, 30 Jan 2014 07:09:37 -0500 From: Don Moore ve3zda@gmail.com Reply-To: AMPRNet working group 44net@hamradio.ucsd.edu To: TAPR xNOS Mailing List nos-bbs@tapr.org, AMPRNet working group 44net@hamradio.ucsd.edu Subject: Re: [44net] [nos-bbs] strange udp broadcasts...
(Please trim inclusions from previous messages) _______________________________________________ I too am getting this and have been for a few weeks now but initiated by a different address...
07:04:00.406011 IP 209.189.196.68 > 192.168.1.150: IP 0.0.0.0.5678 > 255.255.255.255.5678: UDP, length 119 (ipip-proto-4) 07:05:00.408246 IP 209.189.196.68 > 192.168.1.150: IP 0.0.0.0.5678 > 255.255.255.255.5678: UDP, length 119 (ipip-proto-4)
73, Don
On Thu, Jan 30, 2014 at 12:49 AM, Jerome Schatten romers@shaw.ca wrote:
44ers...
So every minute of every hour of every day, I get this below; it started several weeks ago. It looks like it's coming from the Ampr portal -- why? 24.84.205.232 is indeed my ip and it seems that 209.84.205.232 is the same ip as the rip broadcasts are coming from. Is there any way to turn this off other than turning off rip?
Wed Jan 29 21:35:27 2014 - tun0 recv: IP: len 167 209.189.196.68->192.168.1.149 ihl 20 ttl 55 DF prot IP IP: len 147 0.0.0.0->255.255.255.255 ihl 20 ttl 64 prot UDP UDP: len 127 5678->5678 Data 119 0000 ..1.....Seattle-ER1....6.7....MikroTik............FLNH-GLS0....R 0040 B2011UAS......................T......ampr-24.84.205.232 (encap) 0.0.0.0->255.255.255.255 UDP 0000 ..1.....Seattle-ER1....6.7....MikroTik............FLNH-GLS0....R 0040 B2011UAS......................T......ampr-24.84.205.232
jerome - ve7ass
nos-bbs mailing list nos-bbs@tapr.org http://www.tapr.org/mailman/listinfo/nos-bbs
Sounds great, thanks....
Don
On Thu, Jan 30, 2014 at 11:45 AM, Tim Osburn 44net@osburn.com wrote:
(Please trim inclusions from previous messages) _______________________________________________ Don, This is mikrotik discovery protocol. I'll talk to the device owner to see if we can turn that off.
Tim Osburn www.osburn.com W7RSZ
On Thu, 30 Jan 2014, Don Moore wrote:
Date: Thu, 30 Jan 2014 07:09:37 -0500
From: Don Moore ve3zda@gmail.com Reply-To: AMPRNet working group 44net@hamradio.ucsd.edu To: TAPR xNOS Mailing List nos-bbs@tapr.org, AMPRNet working group 44net@hamradio.ucsd.edu
Subject: Re: [44net] [nos-bbs] strange udp broadcasts...
(Please trim inclusions from previous messages) _______________________________________________ I too am getting this and have been for a few weeks now but initiated by a different address...
07:04:00.406011 IP 209.189.196.68 > 192.168.1.150: IP 0.0.0.0.5678 > 255.255.255.255.5678: UDP, length 119 (ipip-proto-4) 07:05:00.408246 IP 209.189.196.68 > 192.168.1.150: IP 0.0.0.0.5678 > 255.255.255.255.5678: UDP, length 119 (ipip-proto-4)
73, Don
On Thu, Jan 30, 2014 at 12:49 AM, Jerome Schatten romers@shaw.ca wrote:
44ers...
So every minute of every hour of every day, I get this below; it started several weeks ago. It looks like it's coming from the Ampr portal -- why? 24.84.205.232 is indeed my ip and it seems that 209.84.205.232 is the same ip as the rip broadcasts are coming from. Is there any way to turn this off other than turning off rip?
Wed Jan 29 21:35:27 2014 - tun0 recv: IP: len 167 209.189.196.68->192.168.1.149 ihl 20 ttl 55 DF prot IP IP: len 147 0.0.0.0->255.255.255.255 ihl 20 ttl 64 prot UDP UDP: len 127 5678->5678 Data 119 0000 ..1.....Seattle-ER1....6.7....MikroTik............FLNH-GLS0....R 0040 B2011UAS......................T......ampr-24.84.205.232 (encap) 0.0.0.0->255.255.255.255 UDP 0000 ..1.....Seattle-ER1....6.7....MikroTik............FLNH-GLS0....R 0040 B2011UAS......................T......ampr-24.84.205.232
jerome - ve7ass
nos-bbs mailing list nos-bbs@tapr.org http://www.tapr.org/mailman/listinfo/nos-bbs
A good thing to do is:
/ip neighbor discovery settings set default=no
you may then create your ipip interfaces.
You will have to dsiable MNDP manually for pre-existing interfaces.
You may keep MNDP enabled within your own network if you want.
vy 73 de Marc, LX1DUC
Quoting Tim Osburn 44net@osburn.com:
(Please trim inclusions from previous messages) _______________________________________________ Don, This is mikrotik discovery protocol. I'll talk to the device owner to see if we can turn that off.
Tim Osburn www.osburn.com W7RSZ
On Thu, 30 Jan 2014, Don Moore wrote:
Date: Thu, 30 Jan 2014 07:09:37 -0500 From: Don Moore ve3zda@gmail.com Reply-To: AMPRNet working group 44net@hamradio.ucsd.edu To: TAPR xNOS Mailing List nos-bbs@tapr.org, AMPRNet working group 44net@hamradio.ucsd.edu Subject: Re: [44net] [nos-bbs] strange udp broadcasts...
(Please trim inclusions from previous messages) _______________________________________________ I too am getting this and have been for a few weeks now but initiated by a different address...
07:04:00.406011 IP 209.189.196.68 > 192.168.1.150: IP 0.0.0.0.5678 > 255.255.255.255.5678: UDP, length 119 (ipip-proto-4) 07:05:00.408246 IP 209.189.196.68 > 192.168.1.150: IP 0.0.0.0.5678 > 255.255.255.255.5678: UDP, length 119 (ipip-proto-4)
73, Don
On Thu, Jan 30, 2014 at 12:49 AM, Jerome Schatten romers@shaw.ca wrote:
44ers...
So every minute of every hour of every day, I get this below; it started several weeks ago. It looks like it's coming from the Ampr portal -- why? 24.84.205.232 is indeed my ip and it seems that 209.84.205.232 is the same ip as the rip broadcasts are coming from. Is there any way to turn this off other than turning off rip?
Wed Jan 29 21:35:27 2014 - tun0 recv: IP: len 167 209.189.196.68->192.168.1.149 ihl 20 ttl 55 DF prot IP IP: len 147 0.0.0.0->255.255.255.255 ihl 20 ttl 64 prot UDP UDP: len 127 5678->5678 Data 119 0000 ..1.....Seattle-ER1....6.7....MikroTik............FLNH-GLS0....R 0040 B2011UAS......................T......ampr-24.84.205.232 (encap) 0.0.0.0->255.255.255.255 UDP 0000 ..1.....Seattle-ER1....6.7....MikroTik............FLNH-GLS0....R 0040 B2011UAS......................T......ampr-24.84.205.232
jerome - ve7ass
nos-bbs mailing list nos-bbs@tapr.org http://www.tapr.org/mailman/listinfo/nos-bbs