Beruflich Dokumente
Kultur Dokumente
"utline
#hat proble$s do %ou need to sol&e' Tool des(riptions )*A ti$e Tool des(riptions are in the +Software, se(tion of the -NA .uide/ http/00lnaguide0software.ht$l
+n$ap <s6 @network rangeC, 1>?. +n$ap <s6 A!A.6D.AE. 02F,2 N$ap/ http/00inse(ure.org0
QuickTime and a TIFF (LZW) decompressor are needed to see this picture.
Tra(eroute notes
Routers need not repl% to tra(eroutes. -a(k of a repl% does not $ean that the router is down. Return traffi( doesn;t ne(essaril% use the sa$e path.
This (an (ause proble$s with firewalls and pa(ket shapers that assu$e the% see the whole (on&ersation. #hen troubleshooting (onne(tion proble$s, %ou $a% want to ha&e the destination send tra(eroutes to %ou as well.
n$ap
.etting n$ap
4ownload fro$ http/00inse(ure.org 7ni? and 9a("S I usuall% re:uire (o$piling fro$ sour(e. #indows binar% a&ailable.
ip$
9ore on I69
#here is it/
AKS/ 0usr0pubsw0sbin0ip$ Note/ this dire(tor% is not in %our default 6AT3. #ild(ards/ +L, 1single (hara(ter2, +M, 1$ultiple (hara(ters2 Run +ip$ <h, to see list of options.
7sing I69/
Netspeed
#eb based speed testing to Stanford ba(kbone/ http/00netspeed.stanford.edu0 or http/00iperf.stanford.edu0 7seful for finding duple? errors 1$is(onfigured hubs or swit(hes2 in the path.
Iperf
5o$$and line testing tool.
5an also run speed tests against netspeed.stanford.edu and iperf.stanford.edu 5an be run in ser&er $ode for testing speed between arbitrar% points 1e.g., within %our network2 http/00dast.nlanr.net06roOe(ts0Iperf0
4356
Troubleshooting 4356
9an% things (an go wrong. 6roble$s are rarel% (aused b% 4356 ser&er una&ailabilit%. Things to (he(k/
#hat I6 is the host getting' Netdb re(ord for the host. 4356 ser&er logs, roa$ing pool utili=ation reports.
7nderstanding 4356
Stanford has two 4356 ser&ers/ dusk and dawn. Info fro$ Netdb is uploaded appro?i$atel% e&er% AP $inutes. .i&e Netdb the ti$e to upload data. At Stanford, 9A5 address infor$ation is re:uired for su((essful 4356. Initial 4356 is a four step pro(ess using broad(astsQ renews are different.
QuickTime and a TIFF (LZW) decompressor are needed to see this picture.
-eases
4356 addresses are &alid for a li$ited period 1wired and wireless2. 3osts will re<(onfir$ their leases halfwa% through the lease period.
5lients use uni(ast dire(tl% to the 4356 ser&er 1(lients ha&e an address and the% know who their ser&er is2. Renew $essage t%pe is used. Nor$al 4356/ 2 da%s Roa$ing 4356/ D2 $inutes
4356 roa$ing
If the Netdb re(ord has a +ho$e, I6 address appropriate for the network where the de&i(e is lo(ated, 4356 ser&ers will send it.
5an ha&e +ho$e, I6 addresses and still be able to roa$ to other networks. 5an ha&e $ultiple +ho$e, addresses bound to ea(h 9A5 address.
If no appropriate address is entered, 4356 will look for a&ailable roa$ing addresses on the lo(al network.
Nu$ber of roa$ing address is spe(ified b% the -NA. 4efined in the Netdb network re(ord. 7suall% there are onl% a handful of roa$ing addresses. 5an easil% run out of the$.
A .?.?.?/
AN2.A6E.R.R/
7sed b% Network self<registration s%ste$. 1SNSR2 5ould also be used b% a rogue. 6robabl% a rogue 4356 ser&er.
Kinding rogues
Tr% pinging the gatewa% that;s being distributed. 7se +arp, (o$$and to get the 9A5 address of the gatewa%. "r use a sniffer if %ou ha&e one. -ook at swit(h 9A5 tables and find the offending hosts. Shut off the port or go ha&e a +(hat,. New Net<to<Swit(h (onfigs blo(k rogue 4356 ser&ersG
All reports are linked fro$ -NA .uide software se(tion/ http/00lnaguide0software.ht$l
4NS
4NS at Stanford
3ost infor$ation is entered in Net48
7ploads to 4356 ser&ers about e&er% AP $inutes. 7ploads to 4NS ser&ers about e&er% hour.
Starts at P $inutes after the hour. Takes about 2 $inutes. Should be done b% F $inutes past the hour. Spe(ifi( info on ti$ing is kept in the Net48 help files.
#ireless
#ireless proble$s
#ireless is slow or una&ailable. Reports (an be &ague. +#ireless is slow on the 2nd floor., Isolating the proble$ (an speed resolution.
>?a(tl% where is the proble$ o((urring' #hat a((ess point is the user (onne(ting to' 4o others ha&e proble$ in the area'
#ireless tools
A((ess point asso(iation/
9a(/ Internet 5onne(t utilit% 65/ ''
A((ess point dis(o&er% for seeing a&ailable A6;s and (hannels/ NetStu$bler, iStu$bler Iperf and Netspeed are useful for (he(king speed proble$s. "ften, a A6 reboot will sol&e the proble$.
A6 Oa(k 1tso2 infor$ation is in Netdb. 5an unplug and replug if ne(essar%.
6a(ket sniffer
Ad&i(e on Sniffing
Need for a sniffer is rare, but in&aluable when %ou need it. Jou will need to set up spe(ial +span, ports on %our swit(hes to see all traffi(.
No need if %ou;re interested in broad(asts and $ulti(asts. 9ost useful for seeing traffi( entering and lea&ing %our net. -earn to use it before %ou need itG
)*A''