CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-11-11
Junior Member
 
Join Date: 2005-11-01
Posts: 8
Rep Power: 0
Avertive has an average reputation (10+)
Default Finding MAC

I'm seeing address spoofing events in the NG (SPLAT R55) log from an address range I'm told is used for server factory default (for imaging via network: 169.254.x.x). I'm also seeing DHCP requests. Based on this evidence, my thoughts are I have a misconfigured server with a DHCP enabled interface that needs to be shutdown (or assigned a static IP).

To assist server admins in finding the misconfigured box, I'm trying to track down the MAC address used in these netbios broadcasts. Without knowing the MAC, it's almost like finding a needle in a haystack.

I first played around with query options within tracker, but was disappointed to find out MAC information is not logged. I then tried a tcpdump, but then concluded I wasn't seeing any packets despite growing logs because the broadcasts were being dropped by NG before tcpdump could hear it. I then thought to try fw monitor, but I've just read that MAC information cannot be captured this way.

Unfortunately I don't have another *nix system in this particular network (if that wasn't already obvious as I'm trying to debug a netbios problem :P), so am really runnin out of options on how to find this MAC address. Anyone have any ideas of what I might try?

I suppose I could do a cpstop and then run the tcpdump (network is still in pre-production), but I'm looking for a less intrusive means.

Thanks!

Last edited by Avertive; 2005-11-11 at 13:59.
Reply With Quote
  #2 (permalink)  
Old 2005-11-12
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: Finding MAC

tcpdump should capture the traffic before CheckPoint sees it and drops it. Otherwise you can also install winpcap (capture program for Windows) and use that the same way on the internal network listening for the IP address.
Reply With Quote
  #3 (permalink)  
Old 2005-11-14
Member
 
Join Date: 2005-10-25
Location: North Brunswick, NJ
Posts: 38
Rep Power: 0
czech12 has an average reputation (10+)
Default Re: Finding MAC

Is the server on a network that is directly connected to the firewall? If so, just try to run an "arp -a" on the firewall. If not, try to run the same command on the switch that the server is connected to.
__________________
====================
Aaron Vivo
CCSE Plus, CCMSE, NSA
====================
Reply With Quote
  #4 (permalink)  
Old 2005-11-14
Junior Member
 
Join Date: 2005-11-01
Posts: 8
Rep Power: 0
Avertive has an average reputation (10+)
Default Re: Finding MAC

This is the oddest thing...my log files continue to grow showing the dhcp traffic (no IP as source, 255.255.255.255 broadcast as destination; udp/67) yet my tcpdump doesn't catch it.

This is what my dump looks like:
[Expert@fw1]# tcpdump -n -e -i eth1 udp port 67

I've also tried:
[Expert@fw1]# tcpdump -n -e -i eth1 host 255.255.255.255

The servers are connected to the same switch as the firewall, but listing the arp table via 'arp -a' won't tell me which MAC is doing the dhcp broadcasts.

I've just installed an IDS on this segment so should be able to track it down with it, although I really hoped I could with the firewall. I still baffled why my tcpdump doesn't see it. Any other ideas how the firewall might get this information?
Reply With Quote
  #5 (permalink)  
Old 2005-11-15
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: Finding MAC

Not sure why your firewall isn't picking it up. Below is the same dump on my firewall:

bent[admin]# tcpdump -n -e -i eth2 host 255.255.255.255
tcpdump: listening on eth2
09:32:34.598163 I 0:c:29:a0:e0:ef ff:ff:ff:ff:ff:ff 0800 342: 0.0.0.0.68 > 255.2
55.255.255.67: xid:0xd374203c [|bootp]
09:32:39.573633 I 0:c:29:a0:e0:ef ff:ff:ff:ff:ff:ff 0800 342: 0.0.0.0.68 > 255.2
55.255.255.67: xid:0xd374203c secs:273 [|bootp]

Only thing I can think of is that I'm doing it on a Nokia.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 21:02.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0