Thursday, September 30, 2010

KISS Troubleshooting

After several hours of troubleshooting wireless and looking through obscure bugs, I had to come back to the Keep It Simple Stupid idea. So I dig through the log files and find a few errors that maybe I will help someone else if they see them.


%APF-4-REGISTER_IPADD_ON_MSCB_FAILED: apf_foreignap.c:1281 Could not Register IP Add on MSCB. MSCB still in init state.

The reason you will see this error is pretty simple. You are getting packets for or from a client (such as ARP requests) and the client doesn't have an IP address yet. Without an IP address, the "MSCB" is said to be in the init state.

%APF-1-CHANGE_ORPHAN_PKT_IP: apf_foreignap.c:

The registered IP address changed leaving packets "orphaned". Note, I saw this in regard to clients not being able to get DHCP and the changing IP address was 169. addresses. This is also a common error with mac clients trying to hold on to old IP addresses.

%DHCP-3-BIND_SRPORT_ERR: dhcp_support.c:374 Binding service port failed.

There is no info on cisco about this error (other than check the bug tool, which has nothing) and I thought this was where my problem lied. The controller was having problems binding the DHCP addresses to the clients. Well low and behold, I found it wasn't that the controller was unable the DHCP response, this message means that there was either no response or an error response. In my case I had run out of addresses, the entire /22 was full. So now I get to enlarge the network and DHCP pool.


So in conclusion, if your clients aren't getting IP addresses, before you dig through obscure bugs and error messages, make sure you pool isn't used up!

Tuesday, September 28, 2010

P@ssw0rd

You know you have been typing too many passwords when you accidently type 3x1t and l0g0ut when you try to exit your network gear...

Monday, September 27, 2010

Use twitter with Geotagging?

I personally don't like the idea of telling the whole internet exactly where I am at any given time, but Josh O'Brian at StaticNat blog points out some business dangers. Do you use geotagging with your tweets or posts? Do you tweet about problems or issues you are having with the network or software to get help? See how that could be a problem?

Click here for Josh's article.

New Internet Wiretap legislation

The Obama administration attempts to send "sweeping new legislation" demanding "all services that enable communications" including blackberry, facebook, peer to peer messaging and Skype have the ability to allow government wiretaps, unencrypting all communications to plain text. http://www.nytimes.com/2010/09/27/us/27wiretap.html

Well first off, this would appear to be a terrible idea. Forcing companies to create backdoors and master private keys is just adding new avenues for attack.

Perhaps this is just one sided journalism, but I noticed they were not able to find any tech or industry professionals to quote in support of this bill, only against. All the "for" quotes are by politicians. This is also an amazingly poor time to bring up something so fiercly unpopular just before November Elections.

Anyway, looking at the technical aspect:

Facebook, I'm sure they store every keystroke ever entered on their site for advertising purposes anyway, so they shouldn't have a problem.

Blackberry, I assume this only includes the encryption built into the default mail program. Users should be able to still encrypt their own messages with a key system if they have the technical knowhow, if blackberry was forced to ban personal encryption from their devices, well I would suspect every major corporation would ditch blackberry. Do you want any joe smoe at an ISP or blackberry corporate being able to view defense data being e-mailed between people at Lockheed Martin or Boeing? I assume this would mean government oversite committees would have to be created (and funded with our tax dollars) for every company dealing with government contracts and want to use a blackberry?

Skype: Ok, so how would this work. Skype is not like vonage or a regular phone company that sends everything through a central office, skype is peer to peer. After the call creation the users are talking to each other, not a skype server. So do wiretapped phones then get re-routed to skype servers? Wouldn't this be noticed and affect service? I'm sure people would make programs to alert them if Skype wasn't being routed directly to the end user.

Peer2Peer Messaging: Well, there is certainly a variety here, from IRC to ICQ to MSN Messenger to google to .... Microsoft and google might be able to keep track of messages fairly easy, but IRC? I can't imagine what it would take to get all the IRC servers around the world to listen to the FBI/NSA. IRC has been part of wars, coups, and rebellions without anyone being able to stop the flow of information. I doubt a US wiretap request for "fear someone might be a terrorist" is going to change that.

My personal oppinion (if you couldn't tell from the post) terrible idea, unpopular politically and socially, and a nightmare of new costs, both trying to implement something like this as well as the lawsuits/profit loss that would come from any new security holes that are created and used by malicious users. This could also destroy consumer confidence in online usages. (yes I just wrote usages because I was too lazy to think of a real word)

The governments only defense was: it worked out with cell phone companies despite fears. Well, lets just say that is comparing apples and oranges.

Cisco IOS Hints and Tricks: EIGRP myths debunked

A very clear explanation of why EIGRP is in no way a Link State Routing Protocol, or a Hybrid.
Cisco IOS Hints and Tricks: EIGRP myths debunked: "Matthew Norwood performed a really thorough EIGRP research and unearthed a lot of myths around it, some of them coming from official documen..."