LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 05-05-2012, 06:15 PM   #1
throes
LQ Newbie
 
Registered: Feb 2011
Posts: 5

Rep: Reputation: 0
Safe to block 255.255.255.255?


There is a steady stream of UDP packets coming into my local network from some random internet address. The UDP packets are all destined for 255.255.255.255. For some reason the firewall on my Comcast gateway doesn't block this even when running in NAT mode. WTF? So I'm seeing all this traffic bleed through onto my LAN and every device is getting hit with the rogue UDP traffic. I have configured the firewall on most of the LAN devices to drop the packets but that doesn't fix the fact that it's spilling into my LAN. This is a static IP account so I can't solve this by just grabbing a new WAN IP from my ISP.

So here's the question. I'm considering asking my ISP to block this upstream. My request would be to block all traffic destined for 255.255.255.255 on my network. Would I regret doing that? Can anyone think of any legitimate reason to allow internet traffic to hit the broadcast IP on my public subnet?

Last edited by throes; 05-05-2012 at 08:35 PM.
 
Old 05-06-2012, 02:08 PM   #2
baldy3105
Member
 
Registered: Jan 2003
Location: Cambridgeshire, UK
Distribution: Mint (Desktop), Debian (Server)
Posts: 891

Rep: Reputation: 184Reputation: 184
Nope, there is no reason why you shouldn't block this, I can't think of any internet protocol that requires it, its just too inefficient a way of communicating.

Can you not block this on your router?
 
Old 05-06-2012, 02:23 PM   #3
jefro
Moderator
 
Registered: Mar 2008
Posts: 22,009

Rep: Reputation: 3629Reputation: 3629Reputation: 3629Reputation: 3629Reputation: 3629Reputation: 3629Reputation: 3629Reputation: 3629Reputation: 3629Reputation: 3629Reputation: 3629
If it is udp then consider blocking all udp.
 
Old 05-06-2012, 02:27 PM   #4
throes
LQ Newbie
 
Registered: Feb 2011
Posts: 5

Original Poster
Rep: Reputation: 0
Hi Pete. Thanks for the reply. I'm the unfortunate recipient of a Comcast SMC cable modem. The price and speed is the best I can find in Sacramento but the modem has the worst firewall in the world. It has two settings, on and off. The broadcast packets just pass right through in both cases. I'm now filtering this using my own firewall but I'd rather the ISP absorb the unwanted packets especially when a single static firewall rule would do the trick on their end.

Again, thanks for the confirmation about blocking inbound 255.255.255.255. Been blocking it since last night. So far so good.

-Throes
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
What is this -> SRC=0.0.0.0 DST=255.255.255.255 LEN=328 TOS=0x00 PREC=0x00 TTL=128 ID carves Linux - Networking 5 08-17-2008 09:26 PM
Are Broadcasts to 255.255.255.255 Routed MQMan Linux - Networking 6 11-23-2005 02:16 PM
Logs full of hits to 255.255.255.255; how to stop logging? mac_phil Mandriva 2 02-23-2004 10:25 AM
UDP broadcast 255.255.255.255 java8964 Linux - Networking 0 10-29-2003 02:05 PM
configuring RH 7 for a subnet mask of 255.255.255.224 CDPL Linux - Networking 2 04-20-2002 09:06 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 12:41 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration