[syslinux] tftpd and broadcast

Geert Stappers stappers at stappers.nl
Mon Sep 4 12:47:19 PDT 2006


On Mon, Sep 04, 2006 at 08:00:35PM +0200, Geert Stappers wrote:
> On Mon, Sep 04, 2006 at 07:42:54PM +0200, Geert Stappers wrote:
> > 
> > Yes, it does reply to broadcasts, but fails on further follow-up.
> > 
> > Below is what I see with a ethernet sniffer like tcpdump.
> > The filter was set on the MAC address of the netbooting Sun UltraSparc5,
> > which got it IP-address .15 by RARP from 172.24.0.10.
> > At address .26 is the HPA tftp daemon which has the file AC18000F.
> > 172.24.0.39 is another tftpd-hpa but hasn't the requested file.
> > 
 <snip/>
> 
> > 19:17:53.308403 IP 172.24.0.26.33375 > 172.24.0.15.14671: UDP, length 516
> > 19:17:54.305522 IP 172.24.0.26.33375 > 172.24.0.15.14671: UDP, length 516
> > 19:17:56.305735 IP 172.24.0.26.33375 > 172.24.0.15.14671: UDP, length 516
> Three replies from the TFTP server.
> 
> > 19:17:58.324567 IP 172.24.0.15.14671 > 172.24.0.26.33375: UDP, length 4
> First Acknowledge from the TFTP client.
> 
> > 19:17:58.324688 IP 172.24.0.26 > 172.24.0.15: ICMP 172.24.0.26 udp port 33375 unreachable, length 40
> TFTP server tells to TFTP client that he is not listing anymore ...
> 

This is with a time-out of three seconds.


20:10:18.369095 rarp who-is 08:00:20:a8:fc:fd tell 08:00:20:a8:fc:fd
20:10:18.379599 rarp reply 08:00:20:a8:fc:fd at 172.24.0.15
20:10:18.381023 IP 172.24.0.15.14841 > 172.24.0.10.69:  17 RRQ "AC18000F" octet 
20:10:18.385433 IP 172.24.0.10.3040 > 172.24.0.15.14841: UDP, length 19
20:10:23.384736 arp who-has 172.24.0.15 tell 172.24.0.39
20:10:24.384629 arp who-has 172.24.0.15 tell 172.24.0.39
20:10:25.384544 arp who-has 172.24.0.15 tell 172.24.0.39
20:10:36.435213 IP 172.24.0.15.14841 > 255.255.255.255.69:  17 RRQ "AC18000F" octet 
20:10:36.440564 arp reply 172.24.0.15 is-at 08:00:20:a8:fc:fd
20:10:36.440671 IP 172.24.0.39.3040 > 172.24.0.15.14841: UDP, length 19
20:10:36.445943 arp reply 172.24.0.15 is-at 08:00:20:a8:fc:fd
20:10:36.445967 IP 172.24.0.25.32802 > 172.24.0.15.14841: UDP, length 19
20:10:41.467498 arp reply 172.24.0.15 is-at 08:00:20:a8:fc:fd
20:10:45.437999 IP 172.24.0.26.33376 > 172.24.0.15.14841: UDP, length 516
20:10:46.489072 arp reply 172.24.0.15 is-at 08:00:20:a8:fc:fd
20:10:46.494440 arp reply 172.24.0.15 is-at 08:00:20:a8:fc:fd
20:10:46.501875 IP 172.24.0.15.14841 > 172.24.0.26.33376: UDP, length 4
20:10:46.501988 IP 172.24.0.26 > 172.24.0.15: ICMP 172.24.0.26 udp port 33376 unreachable, length 40
20:10:50.513489 IP 172.24.0.15.14841 > 172.24.0.26.33376: UDP, length 4
20:10:50.513539 IP 172.24.0.26 > 172.24.0.15: ICMP 172.24.0.26 udp port 33376 unreachable, length 40
20:10:54.525585 IP 172.24.0.15.14841 > 172.24.0.26.33376: UDP, length 4
20:10:54.525636 IP 172.24.0.26 > 172.24.0.15: ICMP 172.24.0.26 udp port 33376 unreachable, length 40
20:10:57.439420 IP 172.24.0.26.33376 > 172.24.0.15.14841: UDP, length 516
20:10:57.440818 IP 172.24.0.15.14841 > 172.24.0.26.33376: UDP, length 4
20:10:57.440937 IP 172.24.0.26 > 172.24.0.15: ICMP 172.24.0.26 udp port 33376 unreachable, length 40
20:11:01.454766 IP 172.24.0.15.14841 > 172.24.0.26.33376: UDP, length 4
20:11:01.454860 IP 172.24.0.26 > 172.24.0.15: ICMP 172.24.0.26 udp port 33376 unreachable, length 40
20:11:05.467315 IP 172.24.0.15.14841 > 172.24.0.26.33376: UDP, length 4
20:11:05.467409 IP 172.24.0.26 > 172.24.0.15: ICMP 172.24.0.26 udp port 33376 unreachable, length 40
20:11:09.478016 IP 172.24.0.15.14841 > 172.24.0.26.33376: UDP, length 4
20:11:09.478108 IP 172.24.0.26 > 172.24.0.15: ICMP 172.24.0.26 udp port 33376 unreachable, length 40
20:11:13.489763 IP 172.24.0.15.14841 > 172.24.0.26.33376: UDP, length 4
20:11:13.489854 IP 172.24.0.26 > 172.24.0.15: ICMP 172.24.0.26 udp port 33376 unreachable, length 40
20:11:14.477274 arp who-has 172.24.0.15 tell 172.24.0.26
20:11:15.477394 arp who-has 172.24.0.15 tell 172.24.0.26
20:11:16.477512 arp who-has 172.24.0.15 tell 172.24.0.26
20:11:17.501722 IP 172.24.0.15.14841 > 172.24.0.26.33376: UDP, length 4
20:11:17.507051 arp reply 172.24.0.15 is-at 08:00:20:a8:fc:fd
20:11:17.507175 IP 172.24.0.26 > 172.24.0.15: ICMP 172.24.0.26 udp port 33376 unreachable, length 40
20:11:21.442282 IP 172.24.0.26.33376 > 172.24.0.15.14841: UDP, length 516
20:11:21.444214 IP 172.24.0.15.14841 > 172.24.0.26.33376: UDP, length 4
20:11:21.444330 IP 172.24.0.26 > 172.24.0.15: ICMP 172.24.0.26 udp port 33376 unreachable, length 40
20:11:25.453763 IP 172.24.0.15.14841 > 172.24.0.26.33376: UDP, length 4
20:11:25.453857 IP 172.24.0.26 > 172.24.0.15: ICMP 172.24.0.26 udp port 33376 unreachable, length 40
20:11:29.465662 IP 172.24.0.15.14841 > 172.24.0.26.33376: UDP, length 4
20:11:29.465758 IP 172.24.0.26 > 172.24.0.15: ICMP 172.24.0.26 udp port 33376 unreachable, length 40
20:11:33.477377 IP 172.24.0.15.14841 > 172.24.0.26.33376: UDP, length 4
20:11:33.477471 IP 172.24.0.26 > 172.24.0.15: ICMP 172.24.0.26 udp port 33376 unreachable, length 40


GSt
-------------- next part --------------
A non-text attachment was scrubbed...
Name: sunbootT3.pcap
Type: application/octet-stream
Size: 5627 bytes
Desc: not available
URL: <http://www.zytor.com/pipermail/syslinux/attachments/20060904/459d27e2/attachment.obj>


More information about the Syslinux mailing list