Re: ARP interfering with Etherboot TFTP?

[email protected] (Geert Stappers) Fri, 3 Mar 2006 20:49:08 +0100
Newsgroups gmane.network.etherboot.devel
Message-ID <[email protected]>
On Fri, Mar 03, 2006 at 05:14:06PM +0000, John Connett/ENG/UK/Plasmon wrote:
> Has anyone experienced problems with ARP interfering with TFTP from
> Etherboot?
> 
> I am attempting to load a FreeBSD kernel and all appears to be going
> well with alternate TFTP Data Packet; TFTP Acknowledgement exchanges.
> Then the TFTP server host sends an ARP Who has and it all falls down!
> 
> It appears that the server end attempts to receive the first TFTP 
> Acknowledgement for Block 10873 but receives ECONNREFUSED and gives 
> up.
> 
> Attached below are details of the datagrams exchanged around the time
> of the problem and the screen output on the Etherboot client system.
> 
> Any thoughts as to the cause of the problem?

Read further for inline comment.

> Thanks in anticipation
> --
> John Connett
> 
> 
> ----------------------------------------------------------------------
> 
> No Time   Source       Destination   Prot Info
> -- ----   ------       -----------   ---- ----
> 54 15.457 10.4.2.152   10.4.2.46     TFTP Data Packet, Block: 10871
               Server    to Client        Data Block n+0

> 55 15.457 10.4.2.46    10.4.2.152    TFTP Acknowledgement, Block: 10871
               Client    to Server        Ack for Data Block n+0

> 56 15.457 10.4.2.152   10.4.2.46     TFTP Data Packet, Block: 10872
            Server    to Client        Data Block n+1

> 57 15.458 10.4.2.46    10.4.2.152    TFTP Acknowledgement, Block: 10872
            Client    to Server        Ack for Data Block n+1

> 58 15.458 10.4.2.152   10.4.2.46     TFTP Data Packet, Block: 10873
            Server    to Client        Data Block n+2

> 59 15.458 skylon.devel 10.4.2.46     ARP Who has 10.4.2.46?  Tell 10.4.2.152
            Intruder  to Client        Who has Client?  Reply to Server

> 60 15.458 10.4.2.46    10.4.2.152    TFTP Acknowledgement, Block: 10873
            Client    to Server        Ack for Data Block n+2

> 61 15.458 10.4.2.46    skylon.devel  ARP 10.4.2.46 is at 00:30:05:83:54:c5
            Client    to Intruder      Client is at my MAC-address

> 62 18.810 10.4.2.46    10.4.2.152    TFTP Acknowledgement, Block: 10873
            Client    to Server        Ack for Data Block n+2

> 63 25.730 10.4.2.46    10.4.2.152    TFTP Acknowledgement, Block: 10873
            Client    to Server        Ack for Data Block n+2

> 64 38.417 10.4.2.46    10.4.2.152    TFTP Acknowledgement, Block: 10873
               Client    to Server        Ack for Data Block n+2

> ----------------------------------------------------------------------

The strange packet is packet #59 where "Intruder" appears the first time.


      .... some thinking time ....



I think Server and Intruder are the same computer. I call that computer "Beiden"
Beiden is busy with being TFTP server at the Server address
and for some reason Beiden asks on the Intruder address the MAC-address
of Client and to reply to Server. In #61 Client answers to Intruder, yes
it should have sent the answer to Server.
In packet #60 acknowledges Client the data from #58, but Beiden doesn't answer. 
Packet #62 comes after 3 seconds nothing heared from Beiden about #60.
The packets #63 and #64 are also saying "Hey Server, let's continue".
But Server Beiden does not answer.

I don't think it is the Client, Etherboot, that goes bzerk.


About ARP:
> 59 15.458 skylon.devel 10.4.2.46     ARP Who has 10.4.2.46?  Tell 10.4.2.152
            Intruder  to Client        Who has Client?  Reply to Server

> 61 15.458 10.4.2.46    skylon.devel  ARP 10.4.2.46 is at 00:30:05:83:54:c5
            Client    to Intruder      Client is at my MAC-address


I think it is a valid 'Address Resolution Protocol' session.



Hope this helps,
Geert Stappers


-------------------------------------------------------
This SF.Net email is sponsored by xPML, a groundbreaking scripting language
that extends applications into web and mobile media. Attend the live webcast
and join the prime developer group breaking into this new coding territory!
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=110944&bid=241720&dat=121642