nejde wake on lan přes router
Moderátor: Don
- markriz
- Nováček

-
- Registrován: 05. říj 2003
nejde wake on lan přes router
co je třeba nastavit abych mohl zapnout pc v síti, když mé je za routerem? Když jsou přímo v jedné tak to jde.
- Bajgy
- Středně pokročilý

- Registrován: 06. čer 2003
- Bydliště: Uherské Hradiště
asi te nepotesim, ale skrze router to mozne asi nebude. Jedine bys mel router ktery toto primo podporuje. (Napr USRobotics 8000A)
problem je v tom, ze abys pocitac probudil musis poslat tzv broadcast paket , ktery obejde vsechny PC v dane siti a ten u nehoz se shoduje MAC adresa s tou, ktera je uvedena v paketu se probudi.
Jenze tento broadcast paket neprojde zvenci skrze ten router.
Pokud chces WoL za routerem pouzivat, musis k tomu vyuzit jine cesty.
problem je v tom, ze abys pocitac probudil musis poslat tzv broadcast paket , ktery obejde vsechny PC v dane siti a ten u nehoz se shoduje MAC adresa s tou, ktera je uvedena v paketu se probudi.
Jenze tento broadcast paket neprojde zvenci skrze ten router.
Pokud chces WoL za routerem pouzivat, musis k tomu vyuzit jine cesty.
- markriz
- Nováček

-
- Registrován: 05. říj 2003
- Dony
- Středně pokročilý

- Registrován: 29. říj 2003
- Bydliště: okr. Mělník
staci poslat magic packet na broadcast adresu subnetu, ve ktere je pocitac, ktery chces probudit.
http://www.depicus.com/wake-on-lan/what ... n-lan.aspx
http://www.depicus.com/wake-on-lan/wake-on-lan-cmd.aspx
http://www.depicus.com/wake-on-lan/what ... n-lan.aspx
http://www.depicus.com/wake-on-lan/wake-on-lan-cmd.aspx
Avatar tancuje, nechce se mu na záchod... - Bajgy
- Středně pokročilý

- Registrován: 06. čer 2003
- Bydliště: Uherské Hradiště
- Dony
- Středně pokročilý

- Registrován: 29. říj 2003
- Bydliště: okr. Mělník
treti odstavec...
Kód: Vybrat vše
Wake on Lan over the Internet (or why is it such a pain in the ****)
"IP directed broadcasts are used in the extremely common and popular "smurf" denial of service attack, and can also be used in related attacks.
An IP directed broadcast is a datagram which is sent to the broadcast address of a subnet to which the sending machine is not directly attached. The directed broadcast is routed through the network as a unicast packet until it arrives at the target subnet, where it is converted into a link-layer broadcast. Because of the nature of the IP addressing architecture, only the last router in the chain, the one that is connected directly to the target subnet, can conclusively identify a directed broadcast. Directed broadcasts are occasionally used for legitimate purposes, but such use is not common outside the financial services industry.
In a "smurf" attack, the attacker sends ICMP echo requests from a falsified source address to a directed broadcast address, causing all the hosts on the target subnet to send replies to the falsified source. By sending a continuous stream of such requests, the attacker can create a much larger stream of replies, which can completely inundate the host whose address is being falsified.
If a Cisco interface is configured with the no ip directed-broadcast command, directed broadcasts that would otherwise be "exploded" into link-layer broadcasts at that interface are dropped instead. Note that this means that no ip directed-broadcast must be configured on every interface of every router that might be connected to a target subnet; it is not sufficient to configure only firewall routers. The no ip directed-broadcast command is the default in Cisco IOS software version 12.0 and later. In earlier versions, the command should be applied to every LAN interface that isn't known to forward legitimate directed broadcasts."
Quoted from Cisco.
Avatar tancuje, nechce se mu na záchod... - markriz
- Nováček

-
- Registrován: 05. říj 2003
- markriz
- Nováček

-
- Registrován: 05. říj 2003
- Bajgy
- Středně pokročilý

- Registrován: 06. čer 2003
- Bydliště: Uherské Hradiště
no to je sice hezke, ale takove pakety obvykle vetsina ISP blokuje, ne? Uz jen proto, ze jejich hranicni routery jsou v defaultni konfiguraci.Dony píše:treti odstavec...Kód: Vybrat vše
Wake on Lan over the Internet (or why is it such a pain in the ****) "IP directed broadcasts are used in the extremely common and popular "smurf" denial of service attack, and can also be used in related attacks. An IP directed broadcast is a datagram which is sent to the broadcast address of a subnet to which the sending machine is not directly attached. The directed broadcast is routed through the network as a unicast packet until it arrives at the target subnet, where it is converted into a link-layer broadcast. Because of the nature of the IP addressing architecture, only the last router in the chain, the one that is connected directly to the target subnet, can conclusively identify a directed broadcast. Directed broadcasts are occasionally used for legitimate purposes, but such use is not common outside the financial services industry. In a "smurf" attack, the attacker sends ICMP echo requests from a falsified source address to a directed broadcast address, causing all the hosts on the target subnet to send replies to the falsified source. By sending a continuous stream of such requests, the attacker can create a much larger stream of replies, which can completely inundate the host whose address is being falsified. If a Cisco interface is configured with the no ip directed-broadcast command, directed broadcasts that would otherwise be "exploded" into link-layer broadcasts at that interface are dropped instead. Note that this means that no ip directed-broadcast must be configured on every interface of every router that might be connected to a target subnet; it is not sufficient to configure only firewall routers. The no ip directed-broadcast command is the default in Cisco IOS software version 12.0 and later. In earlier versions, the command should be applied to every LAN interface that isn't known to forward legitimate directed broadcasts." Quoted from Cisco.
- Dony
- Středně pokročilý

- Registrován: 29. říj 2003
- Bydliště: okr. Mělník
- dayslipper
- Nováček

-
- Registrován: 22. bře 2008
Mám také Edimax BR-6104K a řeším ten samý problém. Přímo v domácí síti není problém zapnout, ale z venku...
U routeru mám nastaveno:
IP Subnet Mask: 255.255.255.0
Ale když se snažím nastavit rozpětí adres na 192.168.2.100-255, tak mi to dovolí jen 100-254.
Následně při Port-Forwardingu 255 pochoptelně také nemohu nastavit.
Co to tedy znamená? Že tento router broadcast neumí?
Manuál zde http://www.edimax.com/en/produce_detail ... &pl2_id=12
Mám ještě jeden dotaz, je opravdu nutné mít namapován port 7,9 příp. 5555 protokolu UDP? viz. tento příspěvek
Ve vnitřní síti mi to funguje s jakýmkoliv portem.
Z vnějšku mám porty namapované od poskytovatele, ale ne přímo tato čísla.
V programu Wake on Lan - Magic Packet port nastavit jde. Ale je fakt že se ta změna portu na 7,9 nebo 5555 dá jednoduše ošetřit funkcí Virtual Server v nastavení routeru. Vyzkoušel jsem to, ale můj pokus byl marný. Uspěch jsem moc nečekal, protože jsem to forwardoval přímo na IP toho počítače a ne ten broadband, který tam tedy asi nejde, ale rád bych znal vaše stanovisko.
V to, že by to byla třeba 192.168.2.254, moc nevěřím.
U routeru mám nastaveno:
IP Subnet Mask: 255.255.255.0
Ale když se snažím nastavit rozpětí adres na 192.168.2.100-255, tak mi to dovolí jen 100-254.
Následně při Port-Forwardingu 255 pochoptelně také nemohu nastavit.
Co to tedy znamená? Že tento router broadcast neumí?
Manuál zde http://www.edimax.com/en/produce_detail ... &pl2_id=12
Mám ještě jeden dotaz, je opravdu nutné mít namapován port 7,9 příp. 5555 protokolu UDP? viz. tento příspěvek
Ve vnitřní síti mi to funguje s jakýmkoliv portem.
Z vnějšku mám porty namapované od poskytovatele, ale ne přímo tato čísla.
V programu Wake on Lan - Magic Packet port nastavit jde. Ale je fakt že se ta změna portu na 7,9 nebo 5555 dá jednoduše ošetřit funkcí Virtual Server v nastavení routeru. Vyzkoušel jsem to, ale můj pokus byl marný. Uspěch jsem moc nečekal, protože jsem to forwardoval přímo na IP toho počítače a ne ten broadband, který tam tedy asi nejde, ale rád bych znal vaše stanovisko.
V to, že by to byla třeba 192.168.2.254, moc nevěřím.