nejde wake on lan přes router

Problematika připojení - hardware i software.

Moderátor: Don

Odpovědět
markriz
Nováček
Nováček
Registrován: 05. říj 2003

nejde wake on lan přes router

Příspěvek od markriz »

co je třeba nastavit abych mohl zapnout pc v síti, když mé je za routerem? Když jsou přímo v jedné tak to jde.
Bajgy
Středně pokročilý
Středně pokročilý
Uživatelský avatar
Registrován: 06. čer 2003
Bydliště: Uherské Hradiště

Příspěvek od Bajgy »

asi te nepotesim, ale skrze router to mozne asi nebude. Jedine bys mel router ktery toto primo podporuje. (Napr USRobotics 8000A)

problem je v tom, ze abys pocitac probudil musis poslat tzv broadcast paket , ktery obejde vsechny PC v dane siti a ten u nehoz se shoduje MAC adresa s tou, ktera je uvedena v paketu se probudi.

Jenze tento broadcast paket neprojde zvenci skrze ten router.
Pokud chces WoL za routerem pouzivat, musis k tomu vyuzit jine cesty.
markriz
Nováček
Nováček
Registrován: 05. říj 2003

Příspěvek od markriz »

routr je edimax br-6104k. Jaky je jiný způsob kromě vyřazení routeru?
Dony
Středně pokročilý
Středně pokročilý
Uživatelský avatar
Registrován: 29. říj 2003
Bydliště: okr. Mělník

Příspěvek od Dony »

staci poslat magic packet na broadcast adresu subnetu, ve ktere je pocitac, ktery chces probudit.
http://www.depicus.com/wake-on-lan/what ... n-lan.aspx
http://www.depicus.com/wake-on-lan/wake-on-lan-cmd.aspx
Obrázek Avatar tancuje, nechce se mu na záchod... :) Windows Vista je tady, řekněte "WTF" :D
Bajgy
Středně pokročilý
Středně pokročilý
Uživatelský avatar
Registrován: 06. čer 2003
Bydliště: Uherské Hradiště

Příspěvek od Bajgy »

takovy paket proleze Internetem?
Dony
Středně pokročilý
Středně pokročilý
Uživatelský avatar
Registrován: 29. říj 2003
Bydliště: okr. Mělník

Příspěvek od Dony »

treti odstavec...

Kód: Vybrat vše

Wake on Lan over the Internet (or why is it such a pain in the ****)

"IP directed broadcasts are used in the extremely common and popular "smurf" denial of service attack, and can also be used in related attacks.

An IP directed broadcast is a datagram which is sent to the broadcast address of a subnet to which the sending machine is not directly attached. The directed broadcast is routed through the network as a unicast packet until it arrives at the target subnet, where it is converted into a link-layer broadcast. Because of the nature of the IP addressing architecture, only the last router in the chain, the one that is connected directly to the target subnet, can conclusively identify a directed broadcast. Directed broadcasts are occasionally used for legitimate purposes, but such use is not common outside the financial services industry.

In a "smurf" attack, the attacker sends ICMP echo requests from a falsified source address to a directed broadcast address, causing all the hosts on the target subnet to send replies to the falsified source. By sending a continuous stream of such requests, the attacker can create a much larger stream of replies, which can completely inundate the host whose address is being falsified.

If a Cisco interface is configured with the no ip directed-broadcast command, directed broadcasts that would otherwise be "exploded" into link-layer broadcasts at that interface are dropped instead. Note that this means that no ip directed-broadcast must be configured on every interface of every router that might be connected to a target subnet; it is not sufficient to configure only firewall routers. The no ip directed-broadcast command is the default in Cisco IOS software version 12.0 and later. In earlier versions, the command should be applied to every LAN interface that isn't known to forward legitimate directed broadcasts."

Quoted from Cisco.
Obrázek Avatar tancuje, nechce se mu na záchod... :) Windows Vista je tady, řekněte "WTF" :D
markriz
Nováček
Nováček
Registrován: 05. říj 2003

Příspěvek od markriz »

zkoušel jsem z té samé stránky verzi pro win. Zadávají se tam úplně stejné údaje jak v příkazovém řádku, tak nevím jestli to pomůže. A angličtina není moje silná stránka

co znamená "staci poslat magic packet na broadcast adresu subnetu" adresu toho pc ? za routrem mám 192.168.2.x a před 192.168.1.x
markriz
Nováček
Nováček
Registrován: 05. říj 2003

Příspěvek od markriz »

a ta jedničková sít je přpojení k net samozřejmě přes router
Bajgy
Středně pokročilý
Středně pokročilý
Uživatelský avatar
Registrován: 06. čer 2003
Bydliště: Uherské Hradiště

Příspěvek od Bajgy »

Dony píše:treti odstavec...

Kód: Vybrat vše

Wake on Lan over the Internet (or why is it such a pain in the ****)

"IP directed broadcasts are used in the extremely common and popular "smurf" denial of service attack, and can also be used in related attacks.

An IP directed broadcast is a datagram which is sent to the broadcast address of a subnet to which the sending machine is not directly attached. The directed broadcast is routed through the network as a unicast packet until it arrives at the target subnet, where it is converted into a link-layer broadcast. Because of the nature of the IP addressing architecture, only the last router in the chain, the one that is connected directly to the target subnet, can conclusively identify a directed broadcast. Directed broadcasts are occasionally used for legitimate purposes, but such use is not common outside the financial services industry.

In a "smurf" attack, the attacker sends ICMP echo requests from a falsified source address to a directed broadcast address, causing all the hosts on the target subnet to send replies to the falsified source. By sending a continuous stream of such requests, the attacker can create a much larger stream of replies, which can completely inundate the host whose address is being falsified.

If a Cisco interface is configured with the no ip directed-broadcast command, directed broadcasts that would otherwise be "exploded" into link-layer broadcasts at that interface are dropped instead. Note that this means that no ip directed-broadcast must be configured on every interface of every router that might be connected to a target subnet; it is not sufficient to configure only firewall routers. The no ip directed-broadcast command is the default in Cisco IOS software version 12.0 and later. In earlier versions, the command should be applied to every LAN interface that isn't known to forward legitimate directed broadcasts."

Quoted from Cisco.
no to je sice hezke, ale takove pakety obvykle vetsina ISP blokuje, ne? Uz jen proto, ze jejich hranicni routery jsou v defaultni konfiguraci.
Dony
Středně pokročilý
Středně pokročilý
Uživatelský avatar
Registrován: 29. říj 2003
Bydliště: okr. Mělník

Příspěvek od Dony »

to je jasne, zalezi na konkretnim pripade, ale principielne to jde
Obrázek Avatar tancuje, nechce se mu na záchod... :) Windows Vista je tady, řekněte "WTF" :D
dayslipper
Nováček
Nováček
Registrován: 22. bře 2008

Příspěvek od dayslipper »

Mám také Edimax BR-6104K a řeším ten samý problém. Přímo v domácí síti není problém zapnout, ale z venku...

U routeru mám nastaveno:
IP Subnet Mask: 255.255.255.0

Ale když se snažím nastavit rozpětí adres na 192.168.2.100-255, tak mi to dovolí jen 100-254.

Následně při Port-Forwardingu 255 pochoptelně také nemohu nastavit.
Co to tedy znamená? Že tento router broadcast neumí?

Manuál zde http://www.edimax.com/en/produce_detail ... &pl2_id=12


Mám ještě jeden dotaz, je opravdu nutné mít namapován port 7,9 příp. 5555 protokolu UDP? viz. tento příspěvek
Ve vnitřní síti mi to funguje s jakýmkoliv portem.
Z vnějšku mám porty namapované od poskytovatele, ale ne přímo tato čísla.
V programu Wake on Lan - Magic Packet port nastavit jde. Ale je fakt že se ta změna portu na 7,9 nebo 5555 dá jednoduše ošetřit funkcí Virtual Server v nastavení routeru. Vyzkoušel jsem to, ale můj pokus byl marný. Uspěch jsem moc nečekal, protože jsem to forwardoval přímo na IP toho počítače a ne ten broadband, který tam tedy asi nejde, ale rád bych znal vaše stanovisko.

V to, že by to byla třeba 192.168.2.254, moc nevěřím.
Odpovědět

Zpět na „Sítě, modemy a Internet“