[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Netboot E250 -- tftp problem



Op 22-01-2008 om 21:31 schreef Hero_xbd!.RRR:
> Geert Stappers wrote:
>>  Could it be firewall software on the TFTP server?
>
> I am using fail2ban[1] on the TFTP server, which functions on iptables and 
> is supposed to modify only "ftp ftps ftp-data ftps-data ssh"ports. Except 
> it, I did not do anything with firewall.

Right now, we don't known what is blocking us,
we have to put fail2ban on the list of suspects ...

> Oh, maybe I should use a shiny minimum debian mechine to act as the TFTP 
> server. That will eliminate various potential blocks.

I think that is a very good option.

> Is it possible the NICs and Net Switch produce the problem?

Unlikely, but put it the bottom of the list with suspects.

> Does the working rarp session eliminate all the possibility?

The RARP session was indeed succesfull.
But RARP is on a different network layer as TFTP is.
So it could indeed that a network component like a switch,
does screw TFTP, but doesn't mangle RARP

> Stappers, I have noticed that your .pcap file also has one packet with 
> checksum error. Does it infer that "checksum error" is in some degree 
> irrelevant?

Rechecking http://www.stappers.nl/gst/temporary/e250/rodebes.pcap
reveals indeed a checksum error. However it is the last TFTP block of the
file. The block size is 28, not the regular 512.
The download is succesfull, the program works fine and there
is surely not 'Data access error'.

I just did `ls > /var/lib/tftpboot/AC18000F` to get less then 512 bytes
in the file that my Sparc (at address 172.24.0.15) downloads with
the 'ok' prompt command `load net`.

The single TFTP packet had according wireshark also a checksum error,
but the transfer was fine. ( checked with `4000 200 55 fill`, `load net`
and `4000 200 dump` )


>
> 1. http://www.fail2ban.org


Cheers
Geert Stappers

P.S.

About latin names:
It is indeed common to use the first name,
it is just me who choose an uncommon family name as nick name.


P.P.S.

I'm subscribed to the mailinglist


Reply to: