Solved

Wierd packets on Sonicwall

Posted on 2011-03-20
4
6,471 Views
Last Modified: 2012-05-11
I see some wierd ethernet packets on my packet monitor in the sonicwall..

Ethernet Header
 Ether Type: 0x32(0x32), Src=[00:1e:f6:c2:1b:15], Dst=[01:00:0c:cc:cc:cd]
Ethernet Type: Unknown
Value:[0]
DROPPED, Drop Code: 1, Module Id: 17, (Ref.Id: _2101_kprwvJqqm) 1:1)

Anybody an idea where this could be comming from?
0
Comment
Question by:socom1985
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 13

Expert Comment

by:Greg Hejl
ID: 35175355
find out what devices belong to the MAC addresses

also search Sonicwall site for drop code table for your firmware version - (do not use tables from other firmware versions)

Ether Type 0x32 appears to be IPSec ESP packet - SW should recognize ESP unless it is a malformed packet...

http://en.wikipedia.org/wiki/List_of_IP_protocol_numbers 
0
 
LVL 24

Accepted Solution

by:
rfc1180 earned 500 total points
ID: 35176247
IP Protocols are not at layer 2, but layer 3, so the EtherType will never be 0x32

Well, what you are seeing is layer 2 traffic and you should NOT see 0x32 in the EtherType, typical values will be ARP and IP (0x0806, 0x0800)

Ether Type: 0x32(0x32), Src=[00:1e:f6:c2:1b:15], Dst=[01:00:0c:cc:cc:cd]
Ethernet Type: Unknown
Value:[0]

The reason you are seeing 'Unknown' is that there is no EtherType of 0x32:
http://www.cavebear.com/archive/cavebear/Ethernet/type.html

The fact that the destination MAC is 01:00:0c:cc:cc:cd and that the EtherType is 0x32 is a host is crafting packets with this information or you are running into some time of bug on the firewall or something else in the path between the host and firewall; additionally, as already stated, the malformed packet is from a hardware issue from a device in path.

If the MAC is not being spoofed, you will need to log into your switches and locate which switchport the mac is located on:
00:1e:f6:c2:1b:15

Billy
0
 
LVL 70

Expert Comment

by:Qlemo
ID: 35406654
This question has been classified as abandoned and is being closed as part of the Cleanup Program. See my comment at the end of the question for more details.
0

Featured Post

Percona Live Europe 2017 | Sep 25 - 27, 2017

The Percona Live Open Source Database Conference Europe 2017 is the premier event for the diverse and active European open source database community, as well as businesses that develop and use open source database software.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …
In this video we outline the Physical Segments view of NetCrunch network monitor. By following this brief how-to video, you will be able to learn how NetCrunch visualizes your network, how granular is the information collected, as well as where to f…
Suggested Courses

626 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question