D-Link DIR-601 :: Log Flooded With UDHCPD Received A SIGUSR1 Entries
Nov 30, 2011
I just replaced my older D-Link with a DIR-601. I decided to try the email feature, so I set the option to "On Log Full". Within an hour I had 5 emails. I noticed that they were mostly entries reading "DIR-601 local0.debug udhcpd[18594]: UDHCPD Received a SIGUSR1". The "Debug Information" option isn't checked.
I have a DIR-601 connected to cable modem. WiFi signal seems to drop randomly. I've been trawling through the logs and I see a lot of "UDHCPD Received a SIGUSR1" Is this related? what it means and how to stabilise the router?
Today i saw on the router dir-655 log file that "UDHCPD Received a SIGTERM" and "received signal 15, good-bye" and the ip address was renewd after 14 days. I want to understand if it's normal behavior of the unit or not. I'm connected to cable modem that is stable more than 15 days.
here is the log of my router:
Oct 23 17:49:48 debug UDHCPD sending ACK to 192.168.0.3 Oct 23 04:01:15 debug Debu: Joining group 224.0.0.252 upstream on IF address 46.117.1.47 Oct 23 04:01:15 debug Debu: Leaving group 224.0.0.252 upstream on IF address 46.117.1.47 Oct 23 03:59:09 debug Debu: Joining group 224.0.0.252 upstream on IF address 46.117.1.47 Oct 23 03:43:58 debug gpio create pidfile /var/run/gpio_wan_green.pid
I bought a DIR-600 a couple of months ago. Days later started experiencing problems, connection would drop, and only way to restore connection was to reset the router.It has its password configured, a secure wireless connection also configured, and Wan Ping is disabled.Yesterday I called D-Link support, and they asked me to update firmware (from 2.03 to 2.05). I did, but problem still here.Today I realized that there is a log section, and when I entered this is what I found?
I have enabled Network filtering on MAC address on my D-Link 628 router.
I've noticed entries in the log file - "Access Denied to LAN System with MAC address ______________" for 2 different MAC addresses. I do not recognize these MAC addresses. The entry that immediately follows these messages - "Above message repeated 466 times and 124 times. The entries for these 2 MAC addresses has been occurring multiple times with different repeat numbers over the past few days.
Is this an indication that someone nearby my router is attempting to hack into my wireless router or do I have a configuration issue?
For our children, we use the parental control feature of the DIR-615 (RevD, FW4.11b15), which works excellently. I use the whitelist feature, so only trusted web sites can be accessed. Unfortunately the DIR-615 only has 10 entries in that list and I will soon need more. So I wonder if there is another D-Link router that offers a bigger list with maybe 50 or even 100 entries?
I have a DIR-655 rev A4 with firmware 1.35NA.I read [URL] 5 which stated that the SECURESPOT feature was removed as of firmware 1.35NA but since upgrading the router to 1.35NA I find the following two log entries mentioning securespot being initiated:
[INFO] Sat Jan 22 21:01:21 2011 Initiating securespot services. [INFO] Sat Jan 22 21:01:21 2011 Allocating securespot services.
I will mention, before upgrading to 1.35NA I was running the stock 1.21 firmware that shipped with this router. Prior to updating to 1.35NA I had taken a backup of the router settings and after the firmware update was applied I restored this settings backup. Could that be the reason this log entry is showing up? It makes me think securespot is not really removed as is claimed in the release notes for this firmware.Can anyone else with a DIR-655 A4 w/firmware 1.35NA confirm the above two log entries mentioning securespot appear in the log (assuming ALL log settings are turned on) when your router is rebooted?
I have a new redundant network with two cores C1 and C2 and five access switches A1 to A5. They are all Cisco SG300 switches. I have noticed there are too many STP messages emanating from one host which has a MAC address which cannot be traced on the network. In the redundant network, I made C1 the root bridge by giving it a priority of 4096 and C2 has been given a priority of 8192 so that it is the secondary root bridge in the network. I have left all other STP settings to default on the rest of the switches in the network.
The problem is that one host is advertising a RST root bridge all the time. Now it has a mac address which is different from the mac address of the root bridge itself and i cannot trace this mac address on the network. Look at the snapshot of Wireshark output in the attach.The source MAC address which is the host advertising all the time is 1c:df:0f:34:db and the root bridge is 1c:df:0f:bb:34:c4.
Why would the root bridge be resetted all the time?I've also noticed that one port in a LAG configuration on one of the access switches is flapping up and down all the time.I tried to troubleshoot this problem. It is not the cable. It would be something else. What could cause this flapping of the port?Could it be related to STP?
On the other Core switch C2 I can see a LAG status switching between forwarding and blocking all the time. What could make the LAG status to flap from forwarding to blocking and back all the time like this?
I use a wireless adapter to connect to our home network but its stopped receiving packets but is sending them. It has worked fine for ages now it just randomly stopped. The network works with everything else (laptops, Xbox and iPods) but my pc wont receive anything. Also our home connection has no password as we live in the middle of nowhere.
I am having a really hard time with a computer that has a wireless connection. Specifically the internet keeps going out. The computer info is that of the affected computer and not the host computer to which the router and modem are connected.
How can I prevent them from seeing the data i receive & send i was told vpn was a route to take but after some searching i found a lot of threads saying different is vpn a best way to go about blocking my isp from seeing data received & sent
I work in a service desk in +100 company and lately i got a task to gather all the host file entries that are on our network's PC's.We operate on windows XP 32&64bit, W7 64bit. Is there any tool that i could use to scan all host files within our network. I tried google of course but maybe i type my search phrases in a bad way to find something useful to my needs.
how to read some of these log entries I see on the IOS 15.2 router I'm working with. I'm fairly new to this stuff. My understanding is that the first socket (123.123.123.123:port#) is the originating one, and the 2nd socket is the receiving or destination. This makes sense when I see an entry like:
01043: *Nov 21 2012 10:28:34.323 PCTime: %FW-6-DROP_PKT: Dropping tcp session xx.xx.241.163:39557 192.168.xx.xx:80 due to RST inside current window with ip ident 0
The internal IP is our email server inside the LAN, the first IP is some IP in a foreign country, so someobody visited our web interface for the email server, obviously trying to breach or recon the interface but whatever. Then I see an (unrelated) entry like this elsewhere in the logs:
001095: *Nov 21 2012 25:56:03.531 PCTime: %FW-6-DROP_PKT: Dropping tcp session xx.xx.178.210:25 192.168.xx.xx:47343 on zone-pair inside-outside class INSIDE-OUTSIDE due to Stray Segment with ip ident 0
What this latter entry tells me is that the Internet host sent data FROM port 25 to what I am guessing is the open port our internal email server must have originated some other communication from. However we do not accept incoming port 25 mail from anywhere but a designated IP so this "send" is not supposed ot occur. So first off, am I reading that correctly? Is the first IP the sending system, and the second IP the receiver? there are no other entries in the logs between these two hosts, so either the logs have truncated with oldest entries removed (log buffer is set to 51200), or that outside host is sending, hoping to get our mail server to respond? BTW, the outside host WHOIS's to Microsoft's IP range, Block 1.
When i check the status of my Internet Connection I notice that the sent and received bytes keeps increasing. I'm sure there are no downloads taking place that I'm aware of. No torrent clients, no antivirus nothing. I checked my PC for malware but that didn't work. As a result of this, i keep getting high pings in online games and can't even watch videos in youtube anymore. like, some software to monitor all the programs that use the itnernet connection without my knowledge or something??My primary concern is gaming (Call of Duty 4) so I wouldn't mind this idle downloading (whatever it is) as long as the major chunk of my internet connection is directed towards Cod4!
This has been happening of late. When i check the status of my connection, i notice that the "sent" and "received" bytes keeps on increasing when i'm idle. I'm pretty much sure there's no downloading of any sort in progress that I'm aware of. As a result of this, I can't watch videos in Youtube or play online games due to high ping.
Belkin F7D4302 will not connect to ISP if I try to manually set DNS entry. Once I attempt this I have to reset the router back to factory defaults before the router will connect with ISP
we are using an ASR 1002 for dynamic NAT (with route maps). I do have a Problem with the usage of the NAT pool it self.The total NAT Translations for the pool are:
#sh ip nat stat [Id: 1] route-map natted-host-01 pool nat-pool-01 refcount 136 pool nat-pool-01: netmask 255.255.254.0 start XX.XX.202.0 end XX.XX.203.255 type generic, total addresses 512, allocated 88 (17%), missee 0
If i now look into the NAT translation Table i do get less entries:
#sh ip nat translations filter map-id dynamic 1 total Total number of translations: 43
Only a deeper look into the QFP gives here the right values:
# sh platform hardware qfp active feature nat data The ouput count matches the values I get if i isue a sh ip nat stat
My question is how is it handled internally.
We do have a problem too, with raising usage of the pool over the time.Once allocated Pool entries are not released after a period of time. And no NAT translation occur for that used IP NAT pool Addresses.
The timer on the device are set: ip nat translation timeout 300 ip nat translation tcp-timeout 900 ip nat translation pptp-timeout 900 ip nat translation udp-timeout 120 ip nat translation routemap-entry-timeout 900 ip nat translation max-entries 750000
I know that the routers communicates using routing protocols and that they forward the ip packets. So I looked in the IP header and the RIP header(for example) and I don`t understands when an packet comes in how does the router understands it`s type? (There`s no byte field to tell him explicitly that this is an ip packet or a rip message)
I was wondering what could cause this, because every time this message shows up in the log I lose internet connection for about 1 minute then it comes back up. Let me know if I need to get any config info.
i can no longer connect to the internet and i have tried everything i could think of. my "wireless network connection status says 0 packets sent and 0 recieved,but im connected to my router with excellent signal. when i got this laptop it had alot of malware, i removed 283entries with malwarebytes in safemode. after i did that i couldnt connect to the internet.
I have an Acer Aspire one that connected perfectly to the internet until I did a reformat. Now it only works if through a wired connection or if the internet does not have a password protection. I have tried on 2 different locations with secure wireless and both have the same result. Packets are sent but not received. All other devices in either location are able to connect to internet through wired or wireless connections.IP address is at 192.xxx and DHCP is enabled, TCP/IP is set to obtain automatically and I deleted and downloaded the newest drivers from the Acer website twice. I also did a winsock reset and tried to clear the arp cache? One of the issues I am getting when I run the diagnostic is "warn default gateway address could not be resolved via arp". I'm not sure how to resolve that.
I reformat my old PC and installed Win XP SP3. There were no errors during installation and everything works ok. However, I'm not able to connect to the internet with my ethernet cable. The LAN connection shows 'Connected' but properties shows some packets sent but zero received. There are no antivirus program installed, windows firewall is turned off as well.
I've tried the following:
- Tried the same ethernet cable connection to another PC and I was able to get on the internet (so no ISP or router issues I assumed).
- Fix the stack using Winsock - didn't work.
- Device Manager now shows Network Adapter > Atheros L2 Fast Ethernet 10/100 Base-T Controller #2 (no yellow question mark). Although I had to reinstall the driver after XP installation.
- Here's the result of ipconfig/all:
Windows IP Configuration Host Name . . . . . . . . . . . . : fiu-cf8cd9c6ded Primary Dns Suffix . . . . . . . : Node Type . . . . . . . . . . . . : Unknown
We have a new router (D Link) at offices which is fixed with LAN wall points on different places , we want to use it .I connected computers to the LAN points with regular lan cables , it gives me the alert (connected) but no bytes received .I tried to ipconfig an here's what i got :Windows IP ConfigurationEthernet adapter Local Area Connection 2[CODE]
I have an HP Workstation that I have been working at constantly to get up and running on the network, it had "OpenCloudSecurity" adaware on it I believe and I was able to get that off with a couple of my freeware tools. The problem I am having is simply it will not connect to the network and only shows. 0Sent 0 Recieved and doesn't pull and IP configuration. I skimmed around and found that sometimes adaware/spyware can play with the TCPIP Stack and that your best bet is to reset the TCPIP stack and WINSOCK ; I did TCPIP Reset and Winsock multiple times with multiple reboots . I know it isn't the ethernet card because I popped in a live Ubuntu CD and it connected just fine on the wired ethernet.
Problem Host A unable to reach Host B, trace route from Host A it reach to Router B but the packet unable reach to the Host B here the 1st level troubleshoot I did
1. Traceroute and ping success from router A to host B
2. Ping success from router B to host B success
I wonder the packet reach to router B but it didnt pass to Host B.
Recently bring up a new Router connected to ISP A and the Netflow collector/server is located in different location and they are connected to ISP B. I have enabled snmp and netflow config on my router(2911) but not receiving the netflow packets are not reaching the server for due to some strange reason whereas other packets like ICMP for snmp are reaching the netflow collector.Finally,I created GRE tunnel between the two locations routers and set the route for the netflow collector/server to the tunnel other end IP. In this way the netflow traffic are reaching successfully to the server.
I am trying to configure a BEFSX41 router which sits behind a Motorola SB 5120 cable modem. Somehow it now shows DNS entries on the basic setup page. Comcast advises me to zero out all those entries. When I make the attempt a message pops up saying the entry is invalid, and when I close the warning the entry reverts. The router is set to get its IP address automatically from the SB 5120.