Gnutella Forums  

Go Back   Gnutella Forums > Gnutella News and Gnutelliums Forums > General Gnutella / Gnutella Network Discussion
Register FAQ The Twelve Commandments Members List Calendar Arcade Find the Best VPN Today's Posts

General Gnutella / Gnutella Network Discussion For general discussion about Gnutella and the Gnutella network.
For discussion about a specific Gnutella client program, please post in one of the client forums above.


 
 
LinkBack Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #3 (permalink)  
Old November 21st, 2001
Novicius
 
Join Date: November 21st, 2001
Posts: 2
jblanchard is flying high
Post

Thanks for the reply.
<Once a node make a connection it may be in touch with thousands of other peers. These peers will regularly try and contact the host to download files or form new gnutella connections. If your firewall's blocking this they'll never get through. >

That could in theory cause a DOS unknowningly. Example, thousands of users start trying to contact a node behind a firewall that identified its IP as a sharer.
After that node shuts off and say later that day the hosts/peers decide to connect to that node and get /dev/null'd by the firewall but they keep retrying until they get a deny or some other form of contact, or perhaps give up after say 4 attempts. While this is fine for less than 100 users, a thousand plus would saturate a T1 easily (luckly we have a DS3). Even though those are small packets of say 1k, when you multiply them by 1300 users = 1.3meg of needless traffic, times the retrys ect. On Monday we calculated (at peek) 150K/sec(about 120 unique IPs some continually attempting) of attempts to contact a broadcast IP on our Net (still don't understand that, lol 255 off of a /24). Anyhow if you were to ask an ISP about that type of traffic it would clearly look like a DOS attempt. But still not sure what was behind the attempts, got over 8meg of syslogs with these attempts. We finally routed the traffic to one of our DMZs and set up a PC just to reply with a FIN then RST and they went away, after several mins. We would have setup a xolox client there, but didn't know what protocol was behind port 6346 till just today.

Take Care
-Joe
Reply With Quote
 


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
no activity starfish13 Open Discussion topics 1 December 17th, 2006 04:37 AM
firewall activity flamewire Connection Problems 2 October 30th, 2006 11:36 AM
Trying to burn video it keeps saying "layout type is incompatible with the disk type" Tamara20 Tips & Tricks 3 July 30th, 2006 05:40 AM
suspicious activity roscoedog Open Discussion topics 12 February 14th, 2003 10:22 AM
Serious hd activity Unregistered Support: General 0 October 7th, 2001 01:26 AM


All times are GMT -7. The time now is 08:31 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 ©2011, Crawlability, Inc.

Copyright © 2020 Gnutella Forums.
All Rights Reserved.