Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    TCP/IP Multicast Address Handling Remote DoS (spank.c)

    Scheduled Pinned Locked Moved Firewalling
    7 Posts 3 Posters 286 Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      saidin
      last edited by

      Hi,

      We are using Nessus scanners to scan all our devices for potential security breaches.

      We got a finding for one of our devices with this vulnerability

      TCP/IP Multicast Address Handling Remote DoS (spank.c)

      In internet the solution suggested is to filter out multicast IP addresses (224.0.0.0/4). So, I have created this rule:

      Interfaces : WAN and LAN
      0743fb18-d487-4dd8-b92f-7ab88889a034-image.png

      I wonder if the community has another workaround/solution for this vulnerability.

      Regards
      Said

      dennypageD johnpozJ 2 Replies Last reply Reply Quote 0
      • dennypageD Offline
        dennypage @saidin
        last edited by

        @saidin Honestly, the stuff at that tenable link is meaningless, and appears to have been written by someone who simply did not understand what multicast is.

        S 1 Reply Last reply Reply Quote 0
        • johnpozJ Offline
          johnpoz LAYER 8 Global Moderator @saidin
          last edited by

          @saidin that isn't even the right rule if you wanted to block that.

          " host responds to TCP packets that are coming from a multicast IP "

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 26.03.1 | Lab VMs 2.8.1, 26.07

          S 1 Reply Last reply Reply Quote 0
          • S Offline
            saidin @johnpoz
            last edited by

            @johnpoz So, the Source should be 224.0.0.0/4 and Destination any. And the rule must be applied for LAN and WAN?

            If so, let me invert the configuration.

            Thanks

            Regards
            Said

            1 Reply Last reply Reply Quote 0
            • S Offline
              saidin @dennypage
              last edited by

              @dennypage well, in any case I need to identify a way to block this thing 😢

              Thanks for your reply

              Regards
              Said

              johnpozJ dennypageD 2 Replies Last reply Reply Quote 0
              • johnpozJ Offline
                johnpoz LAYER 8 Global Moderator @saidin
                last edited by

                @saidin if your goal is block scanner from triggering this finding.

                Where are you running the scanner from? outside or inside? but yeah the would need to be source not destination.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 26.03.1 | Lab VMs 2.8.1, 26.07

                1 Reply Last reply Reply Quote 0
                • dennypageD Offline
                  dennypage @saidin
                  last edited by

                  @saidin said in TCP/IP Multicast Address Handling Remote DoS (spank.c):

                  @dennypage well, in any case I need to identify a way to block this thing 😢

                  Before you can block anything, you need to understand what’s actually happening. The information at that link might sound good, but is rather meaningless (like an AI summary). 🫣

                  I would recommend capturing packets to determine what is actually happening. This is the only way to make an informed decision.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                  Privacy Policy · Cookie Policy