• April 26, 2024, 05:00:38 AM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: [SOLVED] TTLOnLowMulticast events on DFL-210  (Read 13347 times)

juanjo

  • Level 2 Member
  • **
  • Posts: 52
[SOLVED] TTLOnLowMulticast events on DFL-210
« on: November 22, 2009, 05:05:25 AM »

Hi:

Searching in the forum for this event i do not find how to avoid it and why is the reason for this event.

My Windows 2008 server wants to do something and perhaps is the discovering of the network devices but I'm not sure of this.

2009-11-22---Warning---IP_PROTO 7000014---TTLOnLowMulticast---UDP---lan---192.168.0.1 224.0.0.252 53457 5355---ttl_low drop.

Can anybody help me and explain me this event and how to avoid it??

Best regards
« Last Edit: November 25, 2009, 10:42:48 AM by juanjo »
Logged

chechito

  • Level 3 Member
  • ***
  • Posts: 193
Re: TTLOnLowMulticast events on DFL-210
« Reply #1 on: November 22, 2009, 08:36:53 AM »

y have seen this with windows vista too, will be interesting know the reason for this logs and if its necessary fix something of simply ignore
Logged

juanjo

  • Level 2 Member
  • **
  • Posts: 52
Re: TTLOnLowMulticast events on DFL-210
« Reply #2 on: November 22, 2009, 10:44:40 AM »

y have seen this with windows vista too, will be interesting know the reason for this logs and if its necessary fix something of simply ignore

In fact, Windows Server 2008 works similarly to Windows Vista in many aspects and one of them can be this one.

The reality is that the log is full of these events.

1.-Perhaps can be for the next reason (LLMNR)??: http://en.wikipedia.org/wiki/Link-local_Multicast_Name_Resolution

2.- We can disable LLMNR also by the next steps: http://www.vistax64.com/vista-networking-sharing/95027-ability-disable-llmnr.html

Can we configure the firewall to answer to these packets ??
It's necessary ?? (it's necessary unregister this type of event, of course)

I hope someone will help us.
« Last Edit: November 22, 2009, 12:12:01 PM by juanjo »
Logged

Fatman

  • Level 9 Member
  • ****
  • Posts: 1675
Re: TTLOnLowMulticast events on DFL-210
« Reply #3 on: November 23, 2009, 08:36:09 AM »

There are a number of local multicast services, the DFL can not participate is the multicast services, but it can act as a multicast router.

These messages are harmless and are generated by any hosts on your network that will search for network services via multicast.

Your options are to either configure the IGMP sections of your DFL, or to create a rule that drops multicast that reaches the DFL.

The first option is the technically correct answer, but it is a lot of configuration.  I usually use the second in most environments.
Logged
non progredi est regredi

juanjo

  • Level 2 Member
  • **
  • Posts: 52
Re: TTLOnLowMulticast events on DFL-210
« Reply #4 on: November 24, 2009, 12:13:25 AM »

Ok, thanks

I will try to drop multicast packets. The doubt is if dropping packets doesn't register more events of this type, that is the question.

I will try it and post the results in the thread. Ok??  :)  :)

Very grateful
Logged

chechito

  • Level 3 Member
  • ***
  • Posts: 193
Re: TTLOnLowMulticast events on DFL-210
« Reply #5 on: November 24, 2009, 05:10:10 AM »

System-Advanced Settings-Ip Settings-Multi-cast TTL on low - drop
Logged

Fatman

  • Level 9 Member
  • ****
  • Posts: 1675
Re: TTLOnLowMulticast events on DFL-210
« Reply #6 on: November 24, 2009, 08:16:12 AM »

Also correct, but I tend to write rules to cover up default actions, so that things are as unambiguous as possible.  Good point.
Logged
non progredi est regredi

juanjo

  • Level 2 Member
  • **
  • Posts: 52
Re: [SOLVED] TTLOnLowMulticast events on DFL-210
« Reply #7 on: November 25, 2009, 10:49:49 AM »

First, thanks to anybody for the help.

In fact, the solution of chechito is the best option for this type of firewall, because the DFL-210 has all mechanisms to drop this type of events without rules.

But the solution of Fatman is more generalist and very interesting, more technical based on performance of devices, and is applied to all kinds of firewalls, in other words, no necessary DLink firewalls.

Thank you very much chechito and Fatman, "Medal of Honor" for both.

Juanjo
Logged

Lavdd

  • Level 1 Member
  • *
  • Posts: 21
Re: [SOLVED] TTLOnLowMulticast events on DFL-210
« Reply #8 on: December 22, 2009, 10:36:36 AM »

I didnt get how to do that without "System-Advanced Settings-Ip Settings-Multi-cast TTL on low - drop"
Logged