TCP MTU and MSS

MTU and MSS are two very important terms we often forget about and not really know what they are. I myself learnt them many time and forgot them later. Knowledge of MTU and MSS comes in handy in different situations. I’ve seen two scenario when MTU and TCP-MSS size was the issue:

  1. spalsh page won’t come up for a wifi AP
  2. subdomain for booking site won’t come up

both the time MTU and TCP-MSS was a cause and it took a while to find this out. So here is some basic of MTU and TCP-MSS.

MTU

A maximum transmission unit (MTU) is the largest packet or frame size, specified in octets (eight-bit bytes) that can be sent in a packet- or frame-based network such as the internet. The internet’s transmission control protocol (TCP) uses the MTU to determine the maximum size of each packet in any transmission. MTU is usually associated with the Ethernet protocol, where a 1500-byte packet is the largest allowed in it (and hence over most of the internet).

One of the most common problems related to MTU is that sometimes higher-level protocols may create packets larger than a particular link supports, and you’ll need to make adjustments to make it work.

To get around this issue, IPv4 allows fragmentation which divides the datagram into pieces. Each piece is small enough to pass over the single link that it is being fragmented for, using the MTU parameter configured for that interface. This fragmentation process takes place at the IP layer (OSI layer 3) and marks the packets it fragments as such. This ensures the IP layer of the destination host knows it should reassemble the packets into the original datagram.

Fragmentation is sometimes not supported by applications, and is something we should avoid if possible. The best way to avoid fragmentation is to adjust the maximum segment size or TCP MSS so the segment will adjust its size before reaching the data link layer.

Before we look at TCP MSS, it helps to understand the build of the  “unit” that’s being sent over the internet.

As mentioned, the common value of MTU in the internet is 1500 bytes.

As you can see in the figure above, the MTU is built from payload (also referred as data) and the TCP and the IP header, 20 bytes each. The total value of the IP and the TCP header is 40 bytes and mandatory for each packet, which leaves us 1460 bytes for our data.

Now, imagine that we are using the GRE protocol in our network, encapsulating the original packet and adding 24 bytes for the GRE header.

The total size of this kind of packet will be 1524 bytes, exceeding the 1500 bytes MTU value. The “data” size in this packet is 1460, but we can and should decrease it in order to make sure the total size will be 1500 bytes or less. And this is where TCP MSS comes into the picture.

TCP MSS, the maximum segment size, is a parameter of the options field of the TCP header that specifies the largest amount of data, specified in bytes, that a computer or communications device can receive in a single TCP segment. It does not include the TCP header or the IP header. This value will dictate the maximum size of the “data” part of the packet. In the following case for the GRE tunnel, we will set the tcp mss value to be 1436 or lower, while the default size is 1460.

The MSS announcement (often mistakenly called a negotiation) is sent during the three-way handshake by both sides, saying: “I can accept TCP segments up to size x”. The size (x) may be larger or smaller than the default. The MSS can be used completely independently in each direction of data flow.

Since the end device will not always know about high level protocols that will be added to this packet along the way, like GRE packets for example, it won’t usually adjust the TCP MSS value. As a result the network devices have the option to rewrite the value of TCP MSS packets that are processed through them. For example, in a Cisco Router the command “ip tcp mss-adjust 1436” in the interface level will rewrite the value of the TCP MSS of any SYN packet that will go via this interface.

Another likely case where a router in transit is carrying out additional encapsulation, that is, MPLS label swapping, this will add an additional label header as below:

This will eventually increase the size of the frame exiting a transiting router (in the case above it is 1508 bytes.) It will also create similar issue for IPSec and IPv6 in IPv4 tunnel etc.

The maximum MTU of an interface will depend on the hardware platform, but the IEEE 802.3 standards require a minimum MTU of 1500 bytes. Also if you notice the following CLI on a router, the maximum IP MTU is capped at the Ethernet MTU of 1500 bytes.

The problem is we cannot increase the IP MTU size on the router Ethernet interface because the MPLS label encapsulation frame size can potentially exceed the maximum MTU. If the source device creates a full size packet with a TCP MSS of 1460 bytes, it is likely this transiting router will drop/fragment the packet. This is bad for our network performance.

What is the best way to solve this?

Shrinking the IP MTU on the interface to 1448 bytes  will create space for 12 additional bytes on the MPLS label header [if you consider a maximum of 3 MPLS label LDP + VPN + TE] plus a 20 byte TCP + 20 byte IP header within a 1500 byte Ethernet MTU.

Please remember, when we shrink the IP MTU on a transiting router, that will also shrink the maximum possible TCP MSS size to 1448 bytes from the source device. If the router does not signal the source and destination during the TCP handshake, the optimal TCP MSS  could potentially create a dropping/fragmentation problem.

Here are the steps to solve this:

Transiting traffic (traffic going via this router):

Router1(config)#int ethernet 1/0
Router1(config-if)#ip mtu 1448

The above command will shrink the IP MTU on the interface to 1448 bytes, creating a 12 byte space for the MPLS label header.

Router1(config-if)#ip tcp adjust-mss ?
<500-1460>
Router1(config-if)#ip tcp adjust-mss 1448

The above command will signal the source and destination device during the three-way handshake to use the TCP MSS size of 1448 bytes so that if they create the full size packet there will still not be any drop/fragmentation on the router. 

Terminating traffic (doing SSH, telnet to this router):

Router1(config)# ip tcp mss 1448?
<68-10000>  MSS

 

https://www.incapsula.com/blog/mtu-mss-explained.html

IP MTU and TCP MSS Missmatch – an evil for network performance

Phishing email from Apple

Getting a lot of phishing emails from Apple these days. I received the below email this morning from the following email address.

First thing I did is to check the domain @idappleicloud.onmirosoft.com . Its kind of a dead giveaway, Apple won’t use domain with the word ‘Microsoft’ in it. Its very important before you click any link from this kind of email, have good look at the email address, specially the domain.

Apρle Reminder <reminder-mail.apple@idappleicloud.onmicrosoft.com>

Then you can google the domain name:

This is what I’ve found from googling:

This actually gives me a lot of insight of the person who is trying to do this phishing.

I can see the

Name: Anne Michelon

Address: 36 VILLA EMILE MEYER

Country: France

Phone: +33.0683845651

Fax: +1.8017659400

 

Google maps even pinpoints the address.

Now very important that you let people know and complain about the email address. In Australia, we have several website where you can do that.

https://www.scamwatch.gov.au/report-a-scam

or from Any country you can report the domain for spam on below website

Report Abuse

 

 

How to always win on sports betting

The title looks like a click bait for sure, however I’ve been writing stuff on this blog just for my pleasure. I personally is not a gambler, I don’t really believe in luck at all and consider myself to be very unlucky. Anyway I sometimes do put very small amount of money when my favorite team is playing and i always used to put money on the team that I support. Being a Bangladesh Cricket fan, Argentina soccer fan, I’ve been burnt before. So this is what I come up with-

“ALWAYS BET AGAINST THE TEAM YOU SUPPORT”

You ask why? very simple:

when you bet against your favorite sports team, there can be only two outcome: either they win or they lose.

If they Win: you lose some money but the pleasure you get for your favorite team win is a WIN

If the Lose: your team loses but at least you made some money so that’s also a WIN.

So by betting against your favorite team you’ll guaranteed to win something. At least I do it this way so i’m not completely lose everything.

Free stuff on your birthday around Sydney

There are a lots of free stuff around Sydney on you birthday. Here is a list of places where they offer free food/drinks etc on your Birthday. There are lots more, but these are the places I like or would like to go.

  1. Free kebab from Ali Baba (collect card in store)
  2.  Birthday voucher with no minimum spend at Bondi Pizza
  3. Free meal at Mancini’s
  4. Free meal at O-Sushi
  5. Free drink from Gloria Jeans
  6. Free drink from Chatime (membership card costs 50c)
  7. Free meal from Nando’s 7 days before to 7 days after birthday (collect card in store or download the app)
  8. Free Meal from Oporto
  9. Free burrito from Salsas 2 days before to 2 days after birthday (need to pick up card at store)
  10. Free 6-inch sub and coke/water from Subway valid during week of birthday
  11. Free salad from Sumo Salad valid for 7 days from birthday (collect card in store):
  12. Free meal (pasta/pizza/salad/antipasti) from Vapiano valid for one week from your birthday
  13. Free scoop of ice cream from Baskin Robbins valid up to around a week after your birthday
  14. Free churros from San Churro for two from 1 day before to 1 day after birthday
  15. Free small frozen yoghurt with topping or regular smoothie or shake from Twisted Frozen Yoghurt valid 7
    days either side of your birthday (collect card in store)
  16. Free Boost Juice for Vibe club members (valid from 2 days before thru 2 days after bday)
  17. Free muffin in the month of your birthday from Muffin Break (collect card in store)
  18. One free game of bowling at AMF Bowling, valid for one month from your birthday

“WannaCry” Ransomware

This weekend there was a big “ransomware” attack called “Wanna Decryptor” AKA “WannaCry”. I think it was 13th May, Saturday started and spread like wildfire across 74 150 cournties, 46,000 200,000 attacks including several major UK hospitals.

This malware first started via email attachment, where users got an email from their bank for transaction check. Once clicked, the ransomware gets activated and encrypts all the file on that machine. Typical ransomware attack a specific computer. However in last Saturdays attack, it uses Windows SMB vulnerability to run an SMBv2 remote code execution in Microsoft Windows. This exploit code name “EternalBlue” made available on the internet through the shadowbrokers on March. It appears that many organizations still haven’t put this patch.

So, the difference between this ransomware and previous typical ransomware is this one is not only attack a specific computer but it can use the Windows vulnerability to attack network computers which doesn’t have the patch installed.

The malware used in this attack, encrypts the files on the computer and asks for $600 in Bitcoins with the wallet details.

Additionally victims wallpaper also change to the following

:

Demo of WanaCry infection in the following Youtube link:

Since bitcoin wallet transactions are open and we can see there are some transaction of $300 before but now the affected computers are getting a request for $600 presumably they’ve increased the ransom.

For convenient bitcoin payments, the malware directs to a page with a QR code at btcfrog, which links to their main bitcoin wallet 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94.

Another bitcoin wallet by the attacker: 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94

In terms of targeted files, the ransomware encrypts files with the following extensions:

.der, .pfx, .key, .crt, .csr, .p12, .pem, .odt, .ott, .sxw, .stw, .uot, .3ds, .max, .3dm, .ods, .ots, .sxc, .stc, .dif, .slk, .wb2, .odp, .otp, .sxd, .std, .uop, .odg, .otg, .sxm, .mml, .lay, .lay6, .asc, .sqlite3, .sqlitedb, .sql, .accdb, .mdb, .dbf, .odb, .frm, .myd, .myi, .ibd, .mdf, .ldf, .sln, .suo, .cpp, .pas, .asm, .cmd, .bat, .ps1, .vbs, .dip, .dch, .sch, .brd, .jsp, .php, .asp, .java, .jar, .class, .mp3, .wav, .swf, .fla, .wmv, .mpg, .vob, .mpeg, .asf, .avi, .mov, .mp4, .3gp, .mkv, .3g2, .flv, .wma, .mid, .m3u, .m4u, .djvu, .svg, .psd, .nef, .tiff, .tif, .cgm, .raw, .gif, .png, .bmp, .jpg, .jpeg, .vcd, .iso, .backup, .zip, .rar, .tgz, .tar, .bak, .tbk, .bz2, .PAQ, .ARC, .aes, .gpg, .vmx, .vmdk, .vdi, .sldm, .sldx, .sti, .sxi, .602, .hwp, .snt, .onetoc2, .dwg, .pdf, .wk1, .wks, .123, .rtf, .csv, .txt, .vsdx, .vsd, .edb, .eml, .msg, .ost, .pst, .potm, .potx, .ppam, .ppsx, .ppsm, .pps, .pot, .pptm, .pptx, .ppt, .xltm, .xltx, .xlc, .xlm, .xlt, .xlw, .xlsb, .xlsm, .xlsx, .xls, .dotx, .dotm, .dot, .docm, .docb, .docx, .doc

 

The “KillSwitch”

A cyber security expert known as “MalwareTech“,  while researching and reverse engineering the malware, found out that the code is requesting a connection to a globally unregistered web address. He immediately bought the domain and then he tested the malware. Once the malware requested the domain and it got a response, it stopped spreading. This is the website the code was requesting:

http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com/

Although this is not a permanent solution for the ransomware, but it stopped it from spreading for the time being. It is very important for people to get the patch immediately : Google MS17-010 exploit or go to the following site.

https://support.microsoft.com/en-us/help/4013389/title

DO NOT click on attachments that you don’t know what they are.

UPDATE Windows OS with the current updates and patches

UPDATE antivirus software

DO NOT download any malware removal tools from internet

DO NOT download torrent files with .exe and click on them

 

Common Ports

7 Echo
19 Chargen
20-21 FTP
22 SSH/SCP
23 Telnet
25 SMTP
42 WINS Replication
43 WHOIS
49 TACACS
53 DNS
67-68 DHCP/BOOTP
69 TFTP
70 Gopher
79 Finger
80 HTTP
88 Kerberos
102 MS Exchange
110 POP3
113 Ident
119 NNTP (Usenet)
123 NTP
135 Microsoft RPC
137-139 NetBIOS
143 IMAP4
161-162 SNMP
177 XDMCP
179 BGP
201 AppleTalk
264 BGMP
318 TSP
381-383 HP Openview
389 LDAP
411-412 Direct Connect
443 HTTP over SSL
445 Microsoft DS
464 Kerberos
465 SMTP over SSL
497 Retrospect
500 ISAKMP
512 rexec
513 rlogin
514 syslog
515 LPD/LPR
520 RIP
521 RIPng (IPv6)
540 UUCP
554 RTSP
546-547 DHCPv6
560 rmonitor
563 NNTP over SSL
587 SMTP
591 FileMaker
593 Microsoft DCOM
631 Internet Printing
636 LDAP over SSL
639 MSDP (PIM)
646 LDP (MPLS)
691 MS Exchange
860 iSCSI
873 rsync
902 VMware Server
989-990 FTP over SSL
993 IMAP4 over SSL
995 POP3 over SSL
1025 Microsoft RPC
1026-1029 Windows Messenger
1080 SOCKS Proxy
1080 MyDoom
1194 OpenVPN
1214 Kazaa
1241 Nessus
1311 Dell OpenManage
1337 WASTE
1433-1434 Microsoft SQL
1512 WINS
1589 Cisco VQP
1701 L2TP
1723 MS PPTP
1725 Steam
1741 CiscoWorks 2000
1755 MS Media Server
1812-1813 RADIUS
1863 MSN
1985 Cisco HSRP
2000 Cisco SCCP
2002 Cisco ACS
2049 NFS
2082-2083 cPanel
2100 Oracle XDB
2222 DirectAdmin
2302 Halo
2483-2484 Oracle DB
2745 Bagle.H
2967 Symantec AV
3050 Interbase DB
3074 XBOX Live
3124 HTTP Proxy
3127 MyDoom
3128 HTTP Proxy
3222 GLBP
3260 iSCSI Target
3306 MySQL
3389 Terminal Server
3689 iTunes
3690 Subversion
3724 World of Warcraft
3784-3785 Ventrilo
4333 mSQL
4444 Blaster
4664 Google Desktop
4672 eMule
4899 Radmin
5000 UPnP
5001 Slingbox
5001 iperf
5004-5005 RTP
5050 Yahoo! Messenger
5060 SIP
5190 AIM/ICQ
5222-5223 XMPP/Jabber
5432 PostgreSQL
5500 VNC Server
5554 Sasser
5631-5632 pcAnywhere
5800 VNC over HTTP
5900+ VNC Server
6000-6001 X11
6112 Battle.net
6129 DameWare
6257 WinMX
6346-6347 Gnutella
6500 GameSpy Arcade
6566 SANE
6588 AnalogX
6665-6669 IRC
6679/6697 IRC over SSL
6699 Napster
6881-6999 BitTorrent
6891-6901 Windows Live
6970 Quicktime
7212 GhostSurf
7648-7649 CU-SeeMe
8000 Internet Radio
8080 HTTP Proxy
8086-8087 Kaspersky AV
8118 Privoxy
8200 VMware Server
8500 Adobe ColdFusion
8767 TeamSpeak
8866 Bagle.B
9100 HP JetDirect
9101-9103 Bacula
9119 MXit
9800 WebDAV
9898 Dabber
9988 Rbot/Spybot
9999 Urchin
10000 Webmin
10000 BackupExec
10113-10116 NetIQ
11371 OpenPGP
12035-12036 Second Life
12345 NetBus
13720-13721 NetBackup
14567 Battlefield
15118 Dipnet/Oddbob
19226 AdminSecure
19638 Ensim
20000 Usermin
24800 Synergy
25999 Xfire
27015 Half-Life
27374 Sub7
28960 Call of Duty
31337 Back Orifice
33434+ traceroute
Legend
Chat
Encrypted
Gaming
Malicious
Peer to Peer
Streaming

Default Wireless router password list

Default Router Passwords List

 Modem Brand Login IP  Username  Password
3Com http://192.168.1.1 admin admin
Belkin http://192.168.2.1
BenQ http://192.168.1.1 admin admin
D-Link http://192.168.0.1 admin
Digicom http://192.168.1.254 admin
Digicom http://192.168.1.254 admin password
Digicom http://192.168.1.254 admin michelangelo
Linksys http://192.168.1.1 admin admin
Netgear http://192.168.0.1 admin password
Sitecom http://192.168.0.1 admin admin
Sitecom http://192.168.0.1 sitecom admin
Thomson http://192.168.1.254 user user
US Robotics http://192.168.1.1 admin admin
TP-Link http://192.168.1.1 admin admin

 

My Favorite Chrome extensions

Chrome extensions are awesome. There are many very useful extensions. I regularly use some of them. Here is a list of very useful chrome extensions that I use everyday:

The Great Suspender

The Great Suspender is very useful when you run a lot of tabs on your chrome. Chrome can be memory heavy when you run multiple tabs. If you always have multiple tabs open on your chrome browser, it can take up lot of memory as in chrome every tab create a new process, takes both processing and memory resource from your pc or laptop.

if you look at the above picture how much memory each tab is using. It hurts when you are running a 4 GB memory. The Great Suspender basically suspends tabs that are not being used in a while and release the memory to the pool.

once you want it back, just hit refresh.

Honey

I actually installed it long time ago, and almost forgot about it until couple of weeks ago. I was purchasing a Frame online, I was about to pay and all of a sudden honey came up on the screen and did its magic and saved me about A$100 fetching a code online. It was great. Honey basically looks for coupon codes online and put the code when you are paying for online shopping.

Momentum

Momentum is a productivity tool, it shows beautiful images in tab background and have the time, says good morning, got a todo list, like this:

Cisco Certified Network Professional

I am now CCNP certified. I’ve been doing this for past 1 year. Finally, today was the TSHOOT exam. Passed and now I’m done. Still, long way to go. For the time being, I will concentrate on Python I guess. Specifically, Network related programming and automation.

I will keep building the labs in my spare time for different topics that I still struggle. Probably more chance that I will take my mind of with Python programming, specifically for Network engineers – to automate boring everyday stuff.

Commbank “CAN’T”

Recently I’ve had (Still having) going through hell with Commonwealth Bank of Australia. It all started when they send me a credit card offer without even letting me know. Long story short, since then commbank did everything wrong and I still don’t have a card. This is still ongoing to this day, so a long version of the story will come shortly (unless this is like one of those posts where I say “to be continued… but never do.)