RE: Traceroute checksum errors

From: Alexander Arsenyev (GU/ETL) (alexander.arsenyev@ericsson.com)
Date: Sun Feb 13 2005 - 10:10:25 GMT-3


Let me guess :-)
The errors are on return path (ICMP TTL Exceeded has wrong ICMP checksum)
and appear only after 6th hop (on 7th and 8th hops). Are you able to capture
ICMP TTL exceeded packets and verify that ICMP checksum is definitely wrong?
Or could it be just 0x0000 which is technically wrong but for a different reason
(botched IP stack implementation)?
Another guess is that you may have incorrectly working NAT after 6th hop which changes
IP addresses embedded into ICMP message but forgets to update ICMP checksum.
HTH,
Cheers
Alex

-----Original Message-----
From: nobody@groupstudy.com [mailto:nobody@groupstudy.com]
Sent: 13 February 2005 12:08
To: ccielab@groupstudy.com
Subject: Traceroute checksum errors

Hi Gurus,

traceroute to (10.222.148.8), 30 hops max, 38 byte packets
 1 x.x.x.x 0.229 ms 0.203 ms 0.192 ms
 2 y.y.y.y 0.223 ms 0.214 ms 0.207 ms
 3 10.0.1.10 0.263 ms 0.251 ms 0.244 ms
 4 10.0.4.97 0.505 ms 0.467 ms 0.861 ms
 5 192.168.52.250 39.225 ms 39.079 ms 38.858 ms
 6 10.222.148.8 40.300 ms 40.550 ms 40.570 ms
 7 10.222.148.8 39.821 ms 40.539 ms 42.491 ms
Icmp checksum is wrong
 8 10.222.148.8 40.068 msIcmp checksum is wrong
  40.314 msIcmp checksum is wrong
  40.588 ms

What can you say about this output? Checksum errors?

Thx



This archive was generated by hypermail 2.1.4 : Thu Mar 03 2005 - 08:51:20 GMT-3