Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Who/what is this IP (modem mode)?

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Virgin Media Services > Virgin Media Internet Service
Register FAQ Community Calendar

Who/what is this IP (modem mode)?
Reply
 
Thread Tools
Old 24-12-2016, 01:10   #1
RainmakerRaw
cf.addict
 
RainmakerRaw's Avatar
 
Join Date: Jan 2010
Services: Gig1
Posts: 230
RainmakerRaw is a glorious beacon of lightRainmakerRaw is a glorious beacon of lightRainmakerRaw is a glorious beacon of lightRainmakerRaw is a glorious beacon of lightRainmakerRaw is a glorious beacon of lightRainmakerRaw is a glorious beacon of lightRainmakerRaw is a glorious beacon of light
Who/what is this IP (modem mode)?

My SH3 is in modem mode, and goes like this:

SH3 > pfSense (APU2C4) > TP-Link 8 port PoE switch
........................................| ethernet clients
........................................| Ubiquiti UAP AC PRO

I currently have the subnets 192.168.100.1 (for the SH3 modem) and 192.168.1.0/24 for the LAN. It used to be 10.x.x.x but that started messing with DHCP from some of my VPN subscriptions so I changed it. Anyway...

I've noticed lately in the firewall logs (pfSense) that there are hits blocked on the WAN side, from 192.168.100.3:138 > 192.168.100.255:138. Does anyone know what's going on there? I assumed it was broadcast related (hence the .255) or NETBIOS/Samba at first (port 138); however if the modem is in transparent bridge mode isn't the only client IP 192.168.100.1? What then is 192.168.100.3 (and by inference, 192.168.100.2)?

Could this be an attempted Smurf attack? Thanks in advance for any info, I'm always wanting to learn something new.
__________________
P-p-p-p-pick up a penguin!
Running Linux and BSD for maximum awesome
RainmakerRaw is offline   Reply With Quote
Advertisement
Old 24-12-2016, 01:25   #2
Paul
Dr Pepper Addict
Cable Forum Team
 
Paul's Avatar
 
Join Date: Oct 2003
Location: Nottingham
Age: 61
Services: Flextel SIP : Sky Mobile : Sky Q TV : VM BB (1000 Mbps) : Aquiss FTTP (330 Mbps)
Posts: 27,717
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Re: Who/what is this IP (modem mode)?

Smurf attacks are normally ICMP based, not tcp/udp.

I assume they are udp hits ?
They certainly look like Netbios broadcasts, but what's sending them is a puzzle.
__________________

Baby, I was born this way.
Paul is offline   Reply With Quote
Old 24-12-2016, 01:42   #3
RainmakerRaw
cf.addict
 
RainmakerRaw's Avatar
 
Join Date: Jan 2010
Services: Gig1
Posts: 230
RainmakerRaw is a glorious beacon of lightRainmakerRaw is a glorious beacon of lightRainmakerRaw is a glorious beacon of lightRainmakerRaw is a glorious beacon of lightRainmakerRaw is a glorious beacon of lightRainmakerRaw is a glorious beacon of lightRainmakerRaw is a glorious beacon of light
Re: Who/what is this IP (modem mode)?

Yes, sorry, they're UDP hits. There are 178 hits in the recent logs for that particular string (192.168.100.3:138 > 192.168.100.255:138). Weird.
__________________
P-p-p-p-pick up a penguin!
Running Linux and BSD for maximum awesome
RainmakerRaw is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 09:50.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.