Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - Zoom ADSL Modem/Gateway

 
Thread Tools Search this Thread
Old 12-09-2004, 03:25 PM   #1
Default Zoom ADSL Modem/Gateway


Thanks in advance for the help....

I've been running a simple DSL-based home network with a basic DSL modem
running into a Linksys router supporting 5 PC's - some Linux, some Windows.
With that configuration, I've always been able to run nmap, or any other
port scanner, at standard speed (normal) settings. We routinely will
perform full scans against our outside client's networks - typically 35-40
IP's at a time.

We've never had a problem with that scan traffic interfering with Internet
activities (web surfing, etc) on the other machines in our network.

Now, in the interest of consolidating devices, we purchased a Zoom ADSL
Gateway (5554) and replaced the modem and Linksys router. Everything works
fine in normal traffic periods, however, whenever we attempt to run an nmap
scan at anything above the -T1 "sneaky" setting, Internet access across the
network for all other machines grinds to a halt.

I can't believe that a higher end gateway can't handle traffic that a basic
modem/Linksys router can. I can find no settings or information related to
any maximum number of connections or seesions that are supported by the
gateway. Zoom tech support also confirmed that it shouldn't be an issue.
Also, the unit only supports logging for system events and not for
incoming/outgoing connections so I can't get any visibility into what's
going on.

Nmap is not sending out that much traffic, so is there anything else I'm
missing? I'm about to return the Zoom and invest in a Netopia or something
else more robust, but want to make sure I don't run into this issue again.

Thanks -

J




Jennifer
  Reply With Quote
Old 12-09-2004, 05:03 PM   #2
donnie
 
Posts: n/a
Default Re: Zoom ADSL Modem/Gateway
On Thu, 9 Dec 2004 09:25:16 -0600, "Jennifer" <>
wrote:

>Thanks in advance for the help....
>
>I've been running a simple DSL-based home network with a basic DSL modem
>running into a Linksys router supporting 5 PC's - some Linux, some Windows.
>With that configuration, I've always been able to run nmap, or any other
>port scanner, at standard speed (normal) settings. We routinely will
>perform full scans against our outside client's networks - typically 35-40
>IP's at a time.
>
>We've never had a problem with that scan traffic interfering with Internet
>activities (web surfing, etc) on the other machines in our network.
>
>Now, in the interest of consolidating devices, we purchased a Zoom ADSL
>Gateway (5554) and replaced the modem and Linksys router. Everything works
>fine in normal traffic periods, however, whenever we attempt to run an nmap
>scan at anything above the -T1 "sneaky" setting, Internet access across the
>network for all other machines grinds to a halt.
>
>I can't believe that a higher end gateway can't handle traffic that a basic
>modem/Linksys router can. I can find no settings or information related to
>any maximum number of connections or seesions that are supported by the
>gateway. Zoom tech support also confirmed that it shouldn't be an issue.
>Also, the unit only supports logging for system events and not for
>incoming/outgoing connections so I can't get any visibility into what's
>going on.
>
>Nmap is not sending out that much traffic, so is there anything else I'm
>missing? I'm about to return the Zoom and invest in a Netopia or something
>else more robust, but want to make sure I don't run into this issue again.
>
>Thanks -
>
>J
>

#########################
Am I correct to assume that there are no problems when nmap is used in
any other mode? My guess is, it's causing a buffer overflow in the
Zoom product. Try other port scanners to see what happens.
donnie.


donnie
  Reply With Quote
Old 12-09-2004, 11:59 PM   #3
Mark
 
Posts: n/a
Default Re: Zoom ADSL Modem/Gateway
Jennifer wrote:
> Thanks in advance for the help....
>
> I've been running a simple DSL-based home network with a basic DSL modem
> running into a Linksys router supporting 5 PC's - some Linux, some Windows.
> With that configuration, I've always been able to run nmap, or any other
> port scanner, at standard speed (normal) settings. We routinely will
> perform full scans against our outside client's networks - typically 35-40
> IP's at a time.
>
> We've never had a problem with that scan traffic interfering with Internet
> activities (web surfing, etc) on the other machines in our network.
>
> Now, in the interest of consolidating devices, we purchased a Zoom ADSL
> Gateway (5554) and replaced the modem and Linksys router. Everything works
> fine in normal traffic periods, however, whenever we attempt to run an nmap
> scan at anything above the -T1 "sneaky" setting, Internet access across the
> network for all other machines grinds to a halt.
>
> I can't believe that a higher end gateway can't handle traffic that a basic
> modem/Linksys router can. I can find no settings or information related to
> any maximum number of connections or seesions that are supported by the
> gateway. Zoom tech support also confirmed that it shouldn't be an issue.
> Also, the unit only supports logging for system events and not for
> incoming/outgoing connections so I can't get any visibility into what's
> going on.
>
> Nmap is not sending out that much traffic, so is there anything else I'm
> missing? I'm about to return the Zoom and invest in a Netopia or something
> else more robust, but want to make sure I don't run into this issue again.
>
> Thanks -
>
> J
>
>

I don't know the technical specs on that product and am having trouble
finding much online. But, I have to wonder if it doesn't have something
to do with the DOS protection they mention. One thing vendors will do
to try and prevent a denial of service attack is to limit the number of
half-open connections. If that's the case then it's not a problem with
the total number of connections, just the half-open ones.

Even at that, I would be surprised that it won't even allow 'polite'
speeds. Anyway...

Out of curiosity, what type of scans have you tried? If it's just tcp
(syn, connect) I'd be curious if the results are any different if you
try a udp scan.

Later,

Mark


Mark
  Reply With Quote
Reply

« test | question »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
VPN to PIX via ADSL modem in router mode tania26 General Help Related Topics 0 07-06-2009 08:40 AM
Am I must wanna use ADSL Spliter? aneslin85 General Help Related Topics 0 10-09-2008 01:49 AM
Cisco 877 ADSL problem connecting gastonp50 Hardware 0 03-30-2008 11:50 AM
Adsl Router > Dual Wan Load Balancing Router > 24 port Switch Hub nazeth Hardware 0 03-28-2007 09:36 AM
Question about preset zoom on TVs and DVD players. Peter Jason DVD Video 0 07-08-2006 01:48 AM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46