Stránka 1 z 1

nejde wake on lan přes router

Napsal: ned 13. úno 2005, 16:53
od markriz
co je třeba nastavit abych mohl zapnout pc v síti, když mé je za routerem? Když jsou přímo v jedné tak to jde.

Napsal: ned 13. úno 2005, 17:52
od Bajgy
asi te nepotesim, ale skrze router to mozne asi nebude. Jedine bys mel router ktery toto primo podporuje. (Napr USRobotics 8000A)

problem je v tom, ze abys pocitac probudil musis poslat tzv broadcast paket , ktery obejde vsechny PC v dane siti a ten u nehoz se shoduje MAC adresa s tou, ktera je uvedena v paketu se probudi.

Jenze tento broadcast paket neprojde zvenci skrze ten router.
Pokud chces WoL za routerem pouzivat, musis k tomu vyuzit jine cesty.

Napsal: ned 13. úno 2005, 17:54
od markriz
routr je edimax br-6104k. Jaky je jiný způsob kromě vyřazení routeru?

Napsal: ned 13. úno 2005, 21:49
od Dony
staci poslat magic packet na broadcast adresu subnetu, ve ktere je pocitac, ktery chces probudit.
http://www.depicus.com/wake-on-lan/what ... n-lan.aspx
http://www.depicus.com/wake-on-lan/wake-on-lan-cmd.aspx

Napsal: ned 13. úno 2005, 22:07
od Bajgy
takovy paket proleze Internetem?

Napsal: ned 13. úno 2005, 22:46
od Dony
treti odstavec...

Kód: Vybrat vše

Wake on Lan over the Internet (or why is it such a pain in the ****)

"IP directed broadcasts are used in the extremely common and popular "smurf" denial of service attack, and can also be used in related attacks.

An IP directed broadcast is a datagram which is sent to the broadcast address of a subnet to which the sending machine is not directly attached. The directed broadcast is routed through the network as a unicast packet until it arrives at the target subnet, where it is converted into a link-layer broadcast. Because of the nature of the IP addressing architecture, only the last router in the chain, the one that is connected directly to the target subnet, can conclusively identify a directed broadcast. Directed broadcasts are occasionally used for legitimate purposes, but such use is not common outside the financial services industry.

In a "smurf" attack, the attacker sends ICMP echo requests from a falsified source address to a directed broadcast address, causing all the hosts on the target subnet to send replies to the falsified source. By sending a continuous stream of such requests, the attacker can create a much larger stream of replies, which can completely inundate the host whose address is being falsified.

If a Cisco interface is configured with the no ip directed-broadcast command, directed broadcasts that would otherwise be "exploded" into link-layer broadcasts at that interface are dropped instead. Note that this means that no ip directed-broadcast must be configured on every interface of every router that might be connected to a target subnet; it is not sufficient to configure only firewall routers. The no ip directed-broadcast command is the default in Cisco IOS software version 12.0 and later. In earlier versions, the command should be applied to every LAN interface that isn't known to forward legitimate directed broadcasts."

Quoted from Cisco.

Napsal: pon 14. úno 2005, 06:38
od markriz
zkoušel jsem z té samé stránky verzi pro win. Zadávají se tam úplně stejné údaje jak v příkazovém řádku, tak nevím jestli to pomůže. A angličtina není moje silná stránka

co znamená "staci poslat magic packet na broadcast adresu subnetu" adresu toho pc ? za routrem mám 192.168.2.x a před 192.168.1.x

Napsal: pon 14. úno 2005, 06:43
od markriz
a ta jedničková sít je přpojení k net samozřejmě přes router

Napsal: pon 14. úno 2005, 08:06
od Bajgy
Dony píše:treti odstavec...

Kód: Vybrat vše

Wake on Lan over the Internet (or why is it such a pain in the ****)

"IP directed broadcasts are used in the extremely common and popular "smurf" denial of service attack, and can also be used in related attacks.

An IP directed broadcast is a datagram which is sent to the broadcast address of a subnet to which the sending machine is not directly attached. The directed broadcast is routed through the network as a unicast packet until it arrives at the target subnet, where it is converted into a link-layer broadcast. Because of the nature of the IP addressing architecture, only the last router in the chain, the one that is connected directly to the target subnet, can conclusively identify a directed broadcast. Directed broadcasts are occasionally used for legitimate purposes, but such use is not common outside the financial services industry.

In a "smurf" attack, the attacker sends ICMP echo requests from a falsified source address to a directed broadcast address, causing all the hosts on the target subnet to send replies to the falsified source. By sending a continuous stream of such requests, the attacker can create a much larger stream of replies, which can completely inundate the host whose address is being falsified.

If a Cisco interface is configured with the no ip directed-broadcast command, directed broadcasts that would otherwise be "exploded" into link-layer broadcasts at that interface are dropped instead. Note that this means that no ip directed-broadcast must be configured on every interface of every router that might be connected to a target subnet; it is not sufficient to configure only firewall routers. The no ip directed-broadcast command is the default in Cisco IOS software version 12.0 and later. In earlier versions, the command should be applied to every LAN interface that isn't known to forward legitimate directed broadcasts."

Quoted from Cisco.
no to je sice hezke, ale takove pakety obvykle vetsina ISP blokuje, ne? Uz jen proto, ze jejich hranicni routery jsou v defaultni konfiguraci.

Napsal: pon 14. úno 2005, 10:10
od Dony
to je jasne, zalezi na konkretnim pripade, ale principielne to jde

Napsal: sob 22. bře 2008, 03:56
od dayslipper
Mám také Edimax BR-6104K a řeším ten samý problém. Přímo v domácí síti není problém zapnout, ale z venku...

U routeru mám nastaveno:
IP Subnet Mask: 255.255.255.0

Ale když se snažím nastavit rozpětí adres na 192.168.2.100-255, tak mi to dovolí jen 100-254.

Následně při Port-Forwardingu 255 pochoptelně také nemohu nastavit.
Co to tedy znamená? Že tento router broadcast neumí?

Manuál zde http://www.edimax.com/en/produce_detail ... &pl2_id=12


Mám ještě jeden dotaz, je opravdu nutné mít namapován port 7,9 příp. 5555 protokolu UDP? viz. tento příspěvek
Ve vnitřní síti mi to funguje s jakýmkoliv portem.
Z vnějšku mám porty namapované od poskytovatele, ale ne přímo tato čísla.
V programu Wake on Lan - Magic Packet port nastavit jde. Ale je fakt že se ta změna portu na 7,9 nebo 5555 dá jednoduše ošetřit funkcí Virtual Server v nastavení routeru. Vyzkoušel jsem to, ale můj pokus byl marný. Uspěch jsem moc nečekal, protože jsem to forwardoval přímo na IP toho počítače a ne ten broadband, který tam tedy asi nejde, ale rád bych znal vaše stanovisko.

V to, že by to byla třeba 192.168.2.254, moc nevěřím.