Link to home
Start Free TrialLog in
Avatar of RGNCM Expert
RGNCM Expert

asked on

66 Byte string in file causes copy to fail over WAN/VPN to remote servers

I am trying to copy a file from WindowsXP across a Sonciwall created VPN to 2 servers on the remote side (Netware6.5 and Linux)

the file is simply (HEX)
000000000  5C 00 61 00 61 00 61-00 61 00 61 00 61 00 61 00
000000010  61 00 61 00 61 00 61-00 61 00 61 00 61 00 61 00
000000020  61 00 61 00 61 00 61-00 61 00 61 00 61 00 61 00
000000030  61 00 61 00 61 00 61-00 61 00 61 00 61 00 61 00
000000040  61 00

{BackSlash} followed by 32 * {NUL}{a} followed by {NUL}

If I try to copy the file from anywhere (Local Disk, Netware Drive, etc) to the remote servers, the copy fails!

This is the smallest subset of characters that will create the failure.  Remove any one or more characters, and it copies just fine.


The connection to the server is not available for about 5-6 seconds afterward, and then, all is fine.

I am not seeing any messages in my firewall about the VPN dropping.
I can still ping the remote server as the error occurs. - So it does not seem to be a VPN drop, but it could be some kind of internal network timeout caused by the inherent VPN delays?

EVEN WORSE: if this sequence is spliced into any other file, the SAME result occurs.
The file starts to copy, then dies when it reaches the sequence.

The file can be copied to ANY OTHER SERVER on our network, and can even be copied to the remote servers directly (not over the VPN) without any problems.

Can anyone think of anything that would cause this "\aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa" sequence to break or pause a VPN, or perhaps make windows THINK there is a problem???

Remember, there are no firewall notifications about a dropped tunnel (either Phase 1 or Phase 2!)

This may be a problem with Windows, as it seems that I can copy the file from my Linux box back across the network without any problem.


This is real puzzler for me, so I'm awarding a high amount to anyone who can help!
Avatar of Michael Worsham
Michael Worsham
Flag of United States of America image

What is the MTU size on the ethernet adapter set for?
ASKER CERTIFIED SOLUTION
Avatar of Bill Bach
Bill Bach
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of billmercer
billmercer

BillBach probably has your answer. A string of 32 'a' characters might be detected as the Welchia worm. No idea why.
Also if it only happens with Windows, might be some antivirus product on the workstation itself.
Avatar of RGNCM Expert

ASKER

@BillBach: Great thought... I will disable the inbound AV on my remote sonicwall and see what happens!

thanks--- Updates to follow
Nailed it right on the head!

The IPS (Intrusion Prevention Service) of the SonicWall was causing the drop.

I simply added an exception from the source addresses, and 'WALLA' (yes I know it's Voila) the problem is gone!

Thank you BillBach