A lot of ghosts UDP connections

Hello

I noticed a huge amount of visible connections by our PIX (running 6.3 (3)). They are all connections, apparently because of DNS traffic. "See the conf:

UDP on 65.110.41.70:53 in 158.64.1.14:2656 idle 0:00:05 flags.

(several thousand)

158.64.1.14 is our DNS server. That the DNS server perform a query looks like this:

11:31:33.291565 158.64.1.14.kana > 65.110.41.70.domain: 3774 [b2 & 3 = 0x10] A [1]? New.awjicomfort.com. (48) (ttl 64, id 42281)

The DNS that is being queried server does not respond to something, so it would be normal to have UDP connections, but the amount is not anywhere close to what it should be.

An approximate count gave me that the DNS server sends queries to the external server to a rate of about 4 requests per second (different queries on the same server). However, the connections see show rather 50 connections whithin a second (based on idle time displayed).

Does anyone know whence this difference? I ca. 65000 connections ghost, due to the 2 servers DNS querying the same host.

Edit: UDP timeout has the default value (0: 02:00)

Gilles

Gilles,

Looks like a known problem - CSCec45748 - new DNS & reset the timer of inactivity of the previous DNS &.

The crux of the problem (as you can see from the title) is that of the existing DNS downtime & are reset when the new DNS & are established. Suggestion at this point would be to go ahead and prosecute TAC and get the latest version of 6.3 (3). This problem has been corrected and checked. Sorry for the trouble.

Scott

Tags: Cisco Security

Similar Questions

  • CRIO 9031 UDP connection

    Hello

    Anyone know if a cRIO 9031 can be set to read a UDP port? I put my cRIO as an FPGA and I do not see the function of UDP connection anywhere. I have walked through and found no examples either. The PIC of these loopholes is attached. Do I need additional software installed in Labview. I'm using LabView 2015 SP1

    Any help is appreciated.

    Hi CEAR,

    It can, but not on the target FPGA.

    The VI you have created is under the FPGA target in the project tree. These support fewer functions than the parties in real time or office that is why you do not find the pallets.

    If you create a new VI by clicking to the right where it says 'Nor-CRIO9031-Test' to the place where it says FPGA and create a new VI then you create a VI in real-time. These can do things more screws can including UDP.

  • TCP/udp connection via the private wifi network

    I want to develop applications using the wireless private network with tcp/udp connection for my Blackberry 8320 (Version 4.2.2.180 without SIM), do I need authorisation from RIM so that they work in the unit? If it is true, how can I get permission?

    I noticed http://www.blackberryforums.com/wifi-hotzone/100800-8320-wi-fi-limited.html

    who says:

    "The Blackberry 8320 with wi - fi connection is limited. The only program that can use the wi - fi is the Blackberry browser... all the third-party programs... ie. Opera Mini, JiveTalk and even RIM's instant messaging programs. Yahoo Messenger, Windows Live Messenger, are all designed to connect using data from EDGE of the phone... None of them can detect or use the wi - fi! »

    If it is true now?

    You can use the interface = wifi parameter in the URL to specify that the connection should be performed by Wi - Fi.  However, please note that this setting is available in version 4.5.0 and highest BlackBerry device software.  Therefore, you must first put your BlackBerry handheld.  FURTER details can be found here:

    What - in different ways to establish an HTTP connection or socket
    Article number: DB-00396

    http://www.BlackBerry.com/knowledgecenterpublic/livelink.exe/fetch/2000/348583/800451/800563/What_Is...

  • UDP connection via wifi in the name of 8320 tunnel met IOException:Invalid

    I am new to Java, trying to open a UDP connection on wifi in my BB8320 (V4.2.2.180).

    I have connected to my 8320 to a WiFi network and that you can access Web page in the browser (configuration: Wi - Fi browser).

    I tried with: Connector.open (DatagramConnection) (datagram://192.168.1.101:5009) and Connector.open (DatagramConnection) (udp://192.168.1.101:5009), but all got IOException:Invalid name of the tunnel.)

    Here's my Mobile Network Options in the camera: Data Services - on; Connection preference - Wi - Fi only.

    The same code works fine in the emulator, tested in a wired network.

    I googled this IOException, it seems that the TCP APN cannot be null, I tried with blackberry.net cmnet, wap.voicestream.com and even the name of the Wi - Fi connection, everyone met time-out problem.

    I have some questions below:

    1. is there any configuration that I missed?

    2. the UDP connection via wifi check the AFN? The APN configured in the emulator is null.

    3. do UDP and TCP connection API need permission in the device?

    Appreciate for any suggestions!

    Sam

    I did in the past, and IIRC the trick was to add: «;» interface = wifi; deviceside = true"to your connection string. for example:

    Connector.Open ("udp://192.168.1.101:5009; interface = wifi; deviceside = true ")"

  • How to set up a Multicast UDP connection? I get the following error: javax.microedition.io.ConnectionNotFoundException

    I need build a Multicas UDP connection, with the following connection string: multicast://224.2.3.4:8888,.
    udpMulticastConnection = (UDPMulticastConnection) Connector.open (" " "multicast://224.2.3.4:8888");

    but I'm javax.microedition.io.ConnectionNotFoundException.

    I read in the doc of the api, I have made a UDPDatagramConnection. I wore the UDPDatagramConnection but the udpMulticast still not do.

    Can someone help me? Please

    Thank you.

    Some useful links:

    https://docs.Oracle.com/JavaME/8.0/API/GCF/API/javax/microedition/IO/package-summary.html

    UDPDatagramConnection (Java (TM) ME generic connection Framework, Version 8 (final JSR360))

    BNF multicast protocol

    Java (TM) ME generic connection Framework, Version 8 (final version of JSR360)

    http://docs.Oracle.com/JavaME/8.0/API/GCF/API/javax/microedition/IO/ConnectionNotFoundException.html

    https://docs.Oracle.com/JavaME/8.0/API/GCF/API/javax/microedition/IO/package-summary.html

    Hello!

    Unfortunately, multicast is not supported by Java ME on RPi. Looks like it still takes much effort to patch raspbian OS itself to support so that we did not continue to support me. Sorry

    Kind regards

    Andrey

  • Localhost UDP connection between FCR and Matlab

    Hi all

    I have a question about the connection between Matlab and FCR UDP. My idea is to Exchange data between Matlab and Labview on the same computer.

    So I found the 'UDP Simple' of the FCR 2.0 sample project where periodically a datasample is generated randomly and sent to the remoteport 61557 local host. In the project a 'fractional number of string for transmission' is used for the transmission of data. The receiver of the sample project reads from the same port to receive the datasample.

    Now, I'm interested to read this simple stream from Matlab (just at first), however, it does not work and I'm not sure why. What I do in Matlab is the following (code Matlab)

    delete variables;
    u = udp ('127.0.0.1', 61557); % Of installation UDP Object
    fopen (u); open reading port %
    A = fread (u, 1);  % read an element
    fclose (u);

    With this code, however, I get a timeout by saying: "' WARNING: unsuccessful reading: the amount of data specified has not been returned within the time limit." "

    I'm not sure why this happens, maybe you could help me out here? I guess that the formet serving to VCF is not the same as in Matlab? Maybe the Terminators are not the same?

    See you soon,.

    Steve0

    Hey

    So, regarding the problem actually, I found the solution today. It was not the firewall, but a simple configuration in Matlab seting the UDP port. So the side of Matlab, to change the definition of udp object according to

    u = udp ('127.0.0.1', 'Thelocalport', 61557);

    If you have

    u = udp ('127.0.0.1', 'Thelocalport', 61557);
    fopen (u);

    A = fread (u)

    fclose (u);
    Delete (u);

    Who does the trick and you can read from the port. Then of course you say Matlab that you read from the "LocalPort" x, which I wasn't aware of.

    On the transmitter side, you simply:

    u = udp ('127.0.0.1', 61557);

    fopen (u);

    fwrite (u, '1');

    fclose (u);
    Delete (u);

    Here, you set just the port of transmiting.

    About the format of the data: I used the simple UDP protocol streaming Comms project where a random number is generated as a double, transformed into a string (ASCII values) and transmitted. At the level of the receiver, you get as much the UDP packet with the ASCII values that you must turn if you want to find the number.

    I hope this helps anyone having the same problem.

    See you soon

  • TCP (UDP) connection with Blackfin

    Hello!

    I BF-537 EZ - KIT Lite and I'm trying to create a simple server in there. I found following problem: listening TCP port does not respect the time-out: it waits until the client establishes the connection for always (value of timeout regardless). Same thing happens to «UDP read» In addition, these screws completely block the execution so the parallel loop is thus blocked. I've found the workaround: If you wrap all timed loop loops, they run all in parallel; the connection listener is still stuck and waiting forever, but the other loops run.

    Is TI WHEREAS behavior? Suggestions to combat it?

    Thank you!


  • FPGA for PC via UDP connection

    Hi all

    Background

    I am currently working on a project to interface an FPGA with a PC, to send a UDP load prepared on the FPGA for the PC. The FPGA is preparing a payload of 18 hexadecimal bytes from h00 8' to 8' h11 and then transmits it via a local network on port 1024, between the FPGA and a second network card in the PC, with static IP assigned to the second network card and the FPGA. Packages leave the FPGA and reached the PC (tested with wireshark) but the vi does not appear meet the payload and display it on the screen in the vi. The vi is based on that comes with labview and only has a few adjustments for most simply to write the final packages saved to a text file.

    Problem:

    Initially, when the vi was run the length of the chain kept evaluate to zero and so he perceived no bytes don't read from the port. I then inserted the flatten channel vi after the UDP read and before the comparison of string length (after reading something on the forum), now the length of the string is not evaluated to zero to 4 instead of this, I also changed the display to the spell option but the same 4 Hexagon keep coming through '0000 0000 0000 0D0A' , but they are not those who have been sent from the FPGA (are they an error message?) and not those taken over by wireshark. In summary, I seem to not be able to read the data of the UDP payload in Labview.

    I tested the VI locally using the Protocol UDP send labview vi and vi (slightly) custom receiver and it still works. The receiver that VI is attached.

    Any suggestions would be great,

    Thank you

    James.

    You can share the wireshark log (preferably in a format based on text that I did not install Wireshark)?

    Are you sure that is no firewall problem? If you are using a firewall, disable it completely for this network card or at least ensure that it accepts connections on UDP Port 1024.

    In addition, set the UDP sender VI on another computer and see if you are still receiving data. If it works, compare logs wireshark compared to what is sent by the FPGA and search for differences. If this does not work, then you have a network like a firewall problem.

  • A UDP connection target FPGA with LabVIEW

    Hello

    I have an FPGA with Ethernet connected to my HOST PC, now I would like to connect the LabVIEW FPGA target and access to its records. Please suggest me.

    Kind regards

    Chetan

    Hi Cheetah,.

    don't know, because I do not know your format or the manual of your FPGA...

  • a lot of problems to connect my camera to the computer

    Hello. I use a USB cable to connect my camera to my computer. When I plugged the camera, windows said that a new found.and of material after only a few seconds, said that your new hardware is installed and ready to use.but at this time the windows reset without any windows alarm.when start-up and I tried to go to my user account, the computer is locked, and after a few minutes I reset. When windows started again and I tried to go to my user account, he says your files and folder lost and create a temporary account for me. After that when I plug in usb cable to my camera to the computer, it does not work and windows could not recognize my camera. I reconnected as administrator and delete my account and create a new. but the files of my older account which was on drive C are not accessible and that they don't remove it from the computer.  I have already installed microsoft security essential and it is up to date. my windows is XP sp3. Idon't think that my computer to the virus. Please help me .thank you.

    Hello

    I suggest you run restore the system to an earlier date when the camera was working properly.
    Here is an article on the hoe for this: http://support.microsoft.com/kb/306084
    Do you see any other matter with he performance of the computer?

  • UDP in 3G connections

    I am trying to create UDP connection 3 G, but I'm getting an IOException: APN not specified.

    Now I've read all the tutorials and son and I try all the ways suggested in these programming tutorials and I use the correct APN for my career. I believe that I properly creates the connections strings and the application works with WIFI but if I disable the wifi it try with 3G and that he simply throws an IOException exception.

    I test on a Bold 9780 with OS6.

    I was wondering if it is possible to limit the device/OS for UDP in 3G or some kind of limitation carrier.

    I can provide the code that I use, but again, I would like to know if there is something of a known issue with this.

      ("udp://:[;]/[|][;tunnelauthusername=;tunnelauthpassword=]");
    

    where:

    • host is the host address in decimal ASCII format with points. The host address can be specified in the format of FULL domain name or an IP address
    • dest_port is the port to send to the host address (optional for the reception)
    • src_port is the local source port (optional)
    • APN is the APN network to string format
    • type specifies the type of connection (UDP)
    • APN username is the user name of the APN authentication in the string format (option if the AFN requires authentication)
    • APN password is the password of APN authentication string format (option if the AFN requires authentication)

    dest_port must be specified to send data on this connection. If src_port is not specified then it is to the same value as default dest_port.

    If the connection should be used to receive data src_port must be specified. dest_port can be excluded inbound connections, which allows the connection to receive all ports of destination multicast datagrams.

    Note: When you test your applications in the simulator of RIM, you must use the following command line switch to open a port for listening:

      /data-port=
    

    If you attempt to send a datagram to a UDP connection and you don't listen on src_port then an IOException is thrown.

    Note: The user of the handheld can select the default behavior for UDP connection. You can override the behavior of ths with the previous parameters described.

    The input and output streams can be acquired via the openInputStream and openOutputStream methods.

  • Connection UDP, AFN and Blackberry signature setting.

    Hello world

    I'm having a problem to launch a connection udp on a blackberry 9000.

    I works well on a device, if I put the APN in the device settings (I am on telstra, the AFN is telstra.internet or telstra.wap)

    If the device does not have the correct apn defined, the udp connection throws an IOException; tunnel failed.

    When I try to put the AFN during the opening of the udp connection, I still get the same IOException.

    I open the connection as follows...

    UDP://serverAddress:ServerPort; localPort/Telstra.Internet

    I was wondering if someone sees something wrong with this, or if the application must be properly signed Blackberry. I could find no information saying that it is one of the RIM not limited of the api, given also that it works very well if the device is configured which leads me to believe that a signature will not fix this problem.

    Thanks for any comments.

    OK I found the problem,

    The url was somehow in the wrong format,

    J2ME, you can open a Udp connection in Server mode by not specifying any addresses, it does not work on blackberry.

  • Check the connections TCP & UDP host through ACL

    Hello!

    I use ACL to control TCP UDP & connections pass through my router (C805 & C2500). I plan to control of the host, but after I have created a new ACL that and add it on IP Access-Group of my Serial interface, the acl that I add before who is used to control the connections TCP & UDP is removed because of an ACL. How can I handle this?

    What you have is a standard access list, which would block anything with the source 127.0.0.1 address and an access list more extended negates several types of traffic.

    To combine I would rewrite the access list standard as a broader access list:

    access-list 100 deny ip 127.0.0.1 host everything

    who deny packets whose source 127.0.0.1 address.

    I would put rewriting stated as first statement in the new list access followed by others which would give you this:

    Note 100 access list refuse the specific host

    access-list 100 deny ip 127.0.0.1 host everything

    Access-list 100 remark block number TCP and UDP ports

    access list 100 permit tcp any any eq www

    access-list 100 permit tcp a whole Workbench

    access-list 100 tcp refuse any any eq 135

    access-list 100 tcp refuse any any eq 445

    access-list 100 tcp refuse any any eq 593

    access-list 100 deny udp any any eq 135

    access-list 100 deny udp any any eq tftp

    access-list 100 deny udp any any eq netbios-ns

    access ip-list 100 permit a whole

    That should do it.

    HTH

    Rick

  • Connections slow UDP of blackBerry Smartphones

    Hello

    I'm building a client/server UDP application similar to the UDP demo which comes with the 9530 Simulator: http://www.blackberry.com/go/udpsample.  This example works fine.  However, at my request, the Simulator sends a UDP message to the server and it is very well run, but when the server sends a message beck to the Simulator, there is a problem.  As far as I can see, the UDP datagram is sent by the server, but the Simulator/client is blocked on the "[UDPDatagramConnection] .receive ([Datagram]) ' command.  It sits there for about 10 seconds, and then must expire or something.  It then responds with the message well received, and all is well.  As far as I can see, no information has been received at the end of this period of 10 seconds, so I guess that is not the problem of the server.  If everything works fine, except this time of 10 seconds.  Of course, since the source code of this function is not provided by RIM, it is impossible to get the debugger in there to see what he's stuck on.  Are there known issues with UDP connections being slow to receive an incoming connection?  Again, my setup is very similar to the example provided by RIM.

    Well, I think that I thought about it.  In my application, I have a main thread running, and the UDP connection is in thread side.  The main thread uses a

    While (udpThreadHasNotFinished & timeout.isAlive ())

    instruction to wait than the thread of the UDP at the end of its activities.  It seems that the main thread is blocked somehow the

    [UDPDatagramConnection] .receive)

    command in the thread of the UDP with the statement 'all'; as soon as the time-out period has expired, the almost finished UDP thread immediately.    This is perhaps due to priorities of the threads or something; I'm not sure.

    In the end, I used a

    UDPThread.join ();

    command in the main thread instead of the command 'everything '.  This makes the main thread wait that the UDP thread to terminate before it proceeds.  RIM too bad decided not to include the function of time-out on the command "join!"

  • UDP receive default buffer size

    Hello

    I have a question about receiving data via UDP:

    Description of the problem:

    An application of part 3 is extract to a PACS + 2400 Hz measurement data.

    All samples are then sent to a UDP port locally.

    I then use a labview application to read the data and perform a treatment.

    The question is, at 2400 Hz I loose a lot of UDP packets because of receive buffer overflow, i.e. new data appear before all the old data is read.

    It's BI data ' in irregular bursts, 10 - 20 times every second.

    I tried increasying the Protocol UDP receive buffer according to this size:

    http://digital.NI.com/public.nsf/allkb/D5AC7E8AE545322D8625730100604F2D

    And it seems to fix the problem.

    But here is another question:

    If I change the size of the UDP buffer during execution of the application of the 3rd part, the 3rd team application will crash.

    So my question is:

    Is it possible to change the value default UDP receive buffer size in windows?

    Such that when the UDP connection is open, it will have a buffer size of 32768 for example, regardless of which application that accesses the UDP connection first?

    Y at - he got another code inside your task of reading as a ms of waiting? Is the task of reading as lean and mean as possible? When you increase the size of the buffer?

    I found this registry key. It may be worth a try. The post was old, it cannot apply to Win7.

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Afd\Parameters \DefaultReceiveWindow (REG_DWORD) = 16384 (decimal)

Maybe you are looking for

  • High-end recommendations 2 gig RAM?

    Hi, I'm looking for a super duper FAST high range that will improve the standard of 1 gig of RAM. Please can anyone recommend any with reasons why its good? Thank you and I love you all.

  • Pavilion dv 6928: vertical lines on the lower part of the screen.

    I met with vertical lines on the bottom of my screen and it's still there. When you restart, sometimes immediately. I read where someone else had the same problem and it would come and go at will... any ideas? See post on 03/01/15

  • A few questions on Satellite P100-188

    Hi, I have a few questions about my new machine I bought recently so please bare with me during their reading... (1) I already owned the P30-145 and the sound was superb. The P100-188 is supposed to have the HD + sound stronger. I don't think so... T

  • Computer interface does not (HP6500A printer)

    I have the HP 6500 has more printer installed with Windows 8.1.  Everything works fine except that I can't open the computer application interface (HP Officejet 6500 E710n-z).  I can print, scan everthing with printer, but does not open the applicati

  • The invisible taskbar icons, can't see the system tray

    (1) programs are still running. When I mouse over them, the ToolTips appear. But I don't see a simple icon, for any program I'm running - being that Steam or Skype. (2) I have followed the good "quick fixes" - disconnected, again, waited, rebooted, e