Securing/Removing DHCPClient from GW (was: Netstat Gateway log)

Information

ID: 559
PHID: PHID-TASK-ggfz4xqvowllgusur5w2
Author: HulaHoop
Status at Migration Time: resolved
Priority at Migration Time: Normal

Description

On the GW the netstat -tulpen output shows dhclient as working on all interfaces including the internal network. This is very bad especially since its not just listening. The only place where dhclient makes sense is the outer NIC of the GW where its a trusted NAT network that assigns dynamic addresses - however it should never be looking at the internal network for anything.

Proto Recv-Q Send-Q Local Address           Foreign Address         State       User       Inode       PID/Program name

udp        0      0 0.0.0.0:16151           0.0.0.0:*                           0          11238       858/dhclient    
udp        0      0 0.0.0.0:68              0.0.0.0:*                           0          11262       858/dhclient    
udp        0      0 10.152.152.10:5300      0.0.0.0:*                           0          18054       3435/tor        
udp6       0      0 ::: (sanitized*)                    :::*                                0          11239                  
            858/dhclient 

*Sanitized since I am not familiar with IPv6 addresses

The Tor UDP connection is unusual too. Any idea what that is about?

Comments


Patrick

2016-09-23 15:38:28 UTC


HulaHoop

2016-09-23 17:52:39 UTC


Patrick

2016-09-23 18:20:52 UTC


Patrick

2016-09-23 18:20:58 UTC


Patrick

2016-09-24 13:33:55 UTC


HulaHoop

2016-09-25 02:11:21 UTC


Patrick

2016-09-25 03:53:32 UTC


HulaHoop

2016-09-25 05:05:17 UTC


HulaHoop

2016-09-25 12:19:57 UTC


Patrick

2016-09-26 18:52:06 UTC


HulaHoop

2016-09-26 22:57:29 UTC


Patrick

2016-09-26 23:21:52 UTC


HulaHoop

2016-09-27 03:29:37 UTC


Patrick

2016-09-27 14:28:40 UTC


HulaHoop

2016-09-27 15:59:19 UTC


Patrick

2016-09-27 22:19:44 UTC


HulaHoop

2016-09-28 13:58:23 UTC


Patrick

2016-09-28 15:10:41 UTC


HulaHoop

2016-09-28 16:44:55 UTC


Patrick

2016-09-28 17:02:59 UTC


HulaHoop

2016-09-28 23:42:31 UTC


HulaHoop

2016-09-28 23:44:58 UTC


Patrick

2016-09-29 00:28:18 UTC


Patrick

2016-09-29 00:31:23 UTC


HulaHoop

2016-09-29 00:50:50 UTC


HulaHoop

2016-09-29 01:10:55 UTC


Patrick

2016-09-29 03:17:08 UTC


HulaHoop

2016-09-29 12:42:09 UTC


HulaHoop

2016-09-29 13:20:52 UTC


Patrick

2016-09-29 17:33:08 UTC


HulaHoop

2016-09-29 20:41:35 UTC


Patrick

2016-09-29 21:03:29 UTC


HulaHoop

2016-09-30 03:19:17 UTC


Patrick

2016-09-30 13:24:19 UTC


HulaHoop

2016-09-30 14:58:10 UTC


Patrick

2016-09-30 15:05:42 UTC


HulaHoop

2016-09-30 19:36:46 UTC


Patrick

2016-09-30 21:24:21 UTC


HulaHoop

2016-10-01 03:10:48 UTC


Patrick

2016-10-01 15:31:16 UTC