Showing posts with label Routers. Show all posts
Showing posts with label Routers. Show all posts

Thursday, May 3, 2007

Debugging a wired Internet connection

Last updated: June 11, 2007
Most Internet connection problems occur using WiFi, but a wired Ethernet connection can also fail. These are some debugging steps to take when an Ethernet based Internet connection isn't working.




Some of this is techie, but I'm working on expanding the explanations of the various steps to make them usable and understandable to more people.

The assumption here is that the router and broadband modem are different physical devices, but the concepts are the same even if they are integrated into a single device.


Technical Background (Added May 6, 2007)

If you are not a techie, this section should provide enough background for you to understand the rest of the steps and procedures.

Computers on the Internet address each other by number. People, of course, address computers on the Internet by name. The "thing" that translates names (google.com, javatester.org) into numbers is a huge system called DNS (Domain Name System). When you can't access a computer on the Internet by name, the problem may be network related, preventing you from in reaching the computer -or- the problem may be in the DNS system. Every request for a computer by name involves an under-the-covers call to the DNS system to translate the name into a number. These calls into the DNS system happen so quickly, you don't notice them.

Network computer nerds don't call the numbers assigned to computers on the Internet numbers, instead they/we use the term "IP address". Simply put, every computer on the Internet has a unique IP address.

Further confusing things for normal folk is the fact that IP addresses are not written like normal numbers. The format used is something like "1.2.3.4". That is, there are four sets of numbers separated by periods instead of commas. IP addresses come up often when debugging Internet connection problems.

You can see the magic of IP addresses by using them to access a web site. For example, you can get to my computergripes.com web site with http://216.92.35.29

To translate a domain name into an IP address your computer makes a request to a computer run by your ISP called a DNS server (a large organization may run their own DNS server computers). This is so important that the standard is to have two available DNS server computers, in case one breaks. I mention this because you must be able to talk to the DNS server of your ISP to reference anything on the Internet by name (referencing a computer by IP address does not involve DNS at all).

For a computer plugged directly into a broadband modem, make a note of the IP addresses of the two DNS servers provided by your ISP. In Windows XP: Control Panel -> Network connections -> Right click on the appropriate connection and get its status -> go to the Support tab -> Click on the Details button. While there also write down the IP address of the default gateway computer.

A computer on a LAN, plugged into a router may be configured to use the DNS servers of the ISP -or- it may be using the router as its DNS server. In the latter case, the router simply passes the DNS request on to the DNS server of your ISP and then passes the response (an IP address) back to you. If your computer(s) is using the DNS servers of your ISP fine. If the router is being used, then log into the internal website in the router and try to find the IP addresses of the DNS servers of your ISP. While there, also make a note of the IP address of the "Default Gateway" computer.

Terminology: Broadband modem refers to either a cable modem or a DSL modem.


Ahead of time

Planning for connection problems should go a long way to debugging them when they occur.

Make a cheat-sheet documenting the normal state of the lights both on the broadband modem and the router. That is, note which lights are normally on, off, blinking, green, orange, etc when things are working. Keep this on paper right next to the router so it can't get lost.

Have a list of some website IP addresses handy (feel free to use the one for computergripes.com above). There is a simple way to learn the IP address of a given website: open a DOS/command window and type "ping myfavoritewebsite.com" without the quotes. The IP address is after "Reply from". The IP address of a website can change over time, so its best to have a few on hand.

www.yahoo.com 66.94.234.13
www.microsoft.com 207.46.197.32
system.opendns.com 208.67.219.60
www.cnet.com 216.239.113.101

Make a note of your DNS server IP addresses and the IP address of the TCP/IP default gateway. The default gateway is the machine between your ISP's internal network and the outside world and may be very handy in narrowing down the problem. Keep it on paper next to the router.

Write the routers IP address and the userid/password for the internal router website and keep it on paper next to the router.

Have an extra router and extra Ethernet cables.

Place an icon in the system tray (a.k.a. notification area, the bottom right corner of the screen, just to the left of the time) for your network connection(s). This tells you at a glance whether Windows thinks the network is connected or not. In Windows XP you do this with: Control Panel -> Network Connections -> Properties of the network connection. Turn on both the checkboxes at the bottom of the General tab (put an icon in notification area when connected and warn me about limited or no connectivity). If there is a red X over the network icon, Windows knows there is trouble. Hovering the mouse over the icon when all is well, provides some useful information.

Have two web browsers available. The only way to tell if your web browser is the source of the problem is to try and access websites using a different browser from the same copy of Windows. Needless to say, Firefox users already have two browsers. For IE users, I suggest the portable version of Firefox available from portableapps.com. Portable applications don't have to be installed, thus minimizing their impact on the system. In other words, Windows doesn't know it's there. Portable applications exist totally in a single folder (making it easy to move them from computer to computer).


When it breaks

Start clean: turn everything off and leave it off for a minute. Then turn on the broadband modem and wait a minute for it to talk to the outside world. Then turn on the router and wait a minute for it to talk to the modem. Then turn on your computer.

Look at the lights on the broadband modem and router to see if they are normal. If the lights on the modem are not in their normal state, then call your ISP. Some ISPs will help with the router, some won't. The lights being wrong in the router only matter if the lights in the modem are normal.

Check the network icon in the system tray. If it has a red X over it, then Windows knows there is something wrong. Try disabling and then re-enabling the network connection.

Try unplugging and replugging all cables.

Try using a different port on the router.

Try using a different Ethernet cable.

Look at the the Ethernet wire at the point where it enters your computer. If it can talk to the router at all, there will be a light or two right next to the plastic connector. And when I say right next to, I mean a few molecules away from the plastic connector. If you see a blinking light then the hardware is working, at least at the lowest level, which is Ethernet.

Also try another computer connected to the router. This will tell you if the first computer is the problem or if the router is.

If the router appears to be the problem:
Try directly connecting to the broadband modem - after turning on your firewall program.
Try an alternate router

If Windows does not see a problem with your network connection, then turn off the firewall program that is running in Windows. Also shut down any anti-Spyware and anti-virus programs. In fact, shut down any and all programs that you can. The general idea is simplify, simplify, simplify until things work again.

Try to access the website inside the router (we saved the IP address of the router for just this reason). This should tell you which side of the router is the problem. If you can get to the website in the router, then you will be prompted for a userid/password. No need to actually log-in.

If you can get to the website in the router, then try accessing websites by their IP address. If websites work by IP address but not by name, then the DNS system is the problem. Your ISP should help with DNS problems, but one thing you can do is wipe out the temporary cache that Windows maintains for DNS. From a Command window (a.k.a. DOS prompt) enter this command: "ipconfig /flushdns". Then try accessing websites by name again.

Also, there are times when one type of Internet activity is blocked but others will work. To narrow down the problem, try email (using software on your computer, not a webpage), FTP, ping, tracert, etc. both by name and by IP address.

If you can get to the router but not the outside world, then log in to the website in the router and:
-Reboot the router.
-Turn off logging and UPnP and remote administration in the router.
-Make sure the firewall is on in the router.
-Update the router firmware.

You may be able to get out of the router, but not to the Internet at large. That is, you may be getting trapped in the internal network of your ISP. To see if that's the case, try ping and trace route to both your normal DNS servers (both of them) and the default gateway. Do this by IP address, not by name. If you can't get to these machines by IP address, the problem is not DNS and not the Internet. In this case, your ISP should be able to help as they are on the hook for access to their DNS server machines and their default gateway machine.

Whew.

Thursday, March 15, 2007

More bad advice from Walter Mossberg

In the March 8, 2007 Mossberg Mailbox column in the Wall Street Journal, a reader asked how he could make sure that no one could piggyback on his WiFi wireless connection. Walter's response was:

"Turn on the password feature in your router, and don't tell anyone the password. You'll usually find the password setting in the installation software that came with the router."

Not quite.

When discussing wireless routers, there are two passwords. I can just imagine the poor reader of the newspaper changing the wrong password and thinking he is safe. False security is worse than no security.

The first password is needed to login to the router itself. Routers have internal websites that you use to make configuration changes, and access to the internal website requires a userid and password. This password has nothing to do with WiFi wireless signals/connections.

By the way, this password should be changed when a new router is installed because all the bad guys know the default passwords. I have an earlier posting on this blog about how important it is to change this router password.

The password that prevents someone from piggybacking on your wireless connection is referred to in all the technical literature as a "key". If the reader looks around the internal router website or the router documentation for a "password", he won't find this. All references to "passwords" refer to the first password, not to the key.

Not to get too technical, but this "key" relates to an encryption standard, either WEP (bad) or WPA (good) or WPA2 (good). And there are good keys and bad ones, an important concept omitted from the response.

So, which password was Mr. Mossberg referring to? Did he have the right concept and use the wrong term, or did he have the wrong concept and use the correct term? Beats me. The PC industry is too new to have a concept of malpractice, but if the shoe fits...



Update: On March 15, 2007 Mr. Mossberg issued a clarification. See Securing a Wireless Network. Certainly a step in the right direction, but...

Quoting: "To enable the encryption key, use the router's setup software to turn on security".

There are multiple mistakes in this sentence.

You enable encryption, you do not enable the encryption key. Encryption is the lock, without the lock, having a combination does nothing.

This ignores the fact that the older type of encryption, WEP, has multiple keys/passwords. Only the newer type (WPA) has a single key/password.

Once the router is working, there is no need to use its setup software. Instead you log in to the internal website in the router to make changes.

You don't "turn on security". What he meant to say was you turn on one of the three types of encryption. Routers have multiple types of security, a point he makes later. Mac address filtering, for example, is a security feature having nothing to do with encryption. So too, disabling remote administration, turning off UPnP and not broadcasting the SSID.

Quoting again: "On newer models, the strongest security system is called WPA..."

WPA is not a security system, it is an encryption system (see above). And, the strongest system is actually WPA2, not WPA.

There is a big omission here: for WPA and WPA2, the length of the key/password is critical. Short is bad, long is good. To encourage long keys/passwords you sometimes see references to a "pass phrase". This means the key/password can be an entire sentence. And it should be. A very long key/password is not an ongoing typing annoyance because it only has to be entered once on each computer that want to access the WiFi network. If your WPA key/password is "dog" or "rose" you have no defense at all from a determined bad guy.

And, WPA is not a single thing. There are multiple types of WPA and the people Mr. Mossberg claims to write for need to be told this. Simply put, home users want WPA-PSK. This is also called WPA Pre-Shared Key and WPA Personal. They do not want WPA with a RADIUS server.

Finally, anyone serious about WiFi security should turn off the WiFi network when not in use. There is an option in the router to turn off the radio transmitter that is the wireless network. No hacker can break into a network that doesn't exist.

Mr. Mossberg is loose or sloppy with words/terminology. When nerds are talking amongst themselves, they can be sloppy with terminology because they all understand anyway. But when writing for a non-technical audience, it is important to be very precise when describing something technical because they don't know the ropes.

And there is no excuse for making technical mistakes, something the editors at the Journal share the blame for. Apparently no one reviews his work.

Saturday, March 3, 2007

Home routers can be dangerous. VERY dangerous.

Most home users with a broadband connection have a router that sits between the cable or DSL modem and their computer(s). If that is you, read this carefully.

On second thought (thanks Leo) everyone should read this posting because the simple question of whether there is a router in your home/office sitting between you and the Internet is not the trivial question it used to be. Way back, broadband modems (cable and DSL) were separate pieces of hardware from routers. No more. So even if there is a single box between your computer(s) and the outside world, it may very well be both the modem and the router.

NOTE: This problem does not affect you if you have a single computer directly connected to a broadband modem that is only a modem and not also a router. Good luck figuring this out. It also does not effect dial-up users. It is very likely to apply to small businesses (large businesses probably have qualified techies configuring their routers). Both wired and wireless WiFi connections are equally vulnerable.


Just by looking at a web page, you can lose your life savings.

Let me explain. A malicious computer program can live inside a web page and run automatically when the page is viewed. This new type of malicious software will modify configuration settings in your router such that when you type in the name of your bank to go to its website, you will instead end up at the website of a bad guy imitating your bank. You enter the userid/password for your bank and the next day there is no money in your accounts.

Nothing is more dangerous than this on the Internet.

Every router has a website built into it that is used for configuring the dozens of options. To make configuration changes you log into this website with a userid/password (the router also has a default IP address that can be used to access its internal website) . For the malicious program to make changes to your router, it needs to know the userid/password. This is only possible if the default password was not changed when the router was installed. That is, if a good computer nerd installed the router you are safe. If your router is still using the default password, change it now!

How can the malicious program know the default userid/password for your router? How can it even know which router you have? It doesn't need to know your exact router model. There are only a handful of companies making the most popular routers. The default userid and password used by these companies is well known. All the program has to do is try them all. It's not a long list.

If you don't know the userid/password to log into your router, I can't stress how important it is to find out. In addition, you also need to know the internal IP address of the router so that you can access it with a web browser.

Let me re-state the problem to hopefully scare you into action. If you enter "www.citibank.com" into your web browser (or use a Favorite/Bookmark) then everyone knows you will go to Citibank's website. But, if you are the victim of this attack, it will not be true. You may end up at a website that looks exactly like Citibank's but is designed for the sole purpose of stealing your userid/password. Even worse, you may end up at the real bank website, but the bad guys could have set themselves up in between you and your bank. Thus, they see everything you enter and all seems perfectly normal because you are, in fact, actually dealing with your bank's website. Just not directly.
Not to pick on Citibank, they are just used as an example.

Computers on the Internet have a unique number assigned to them. They talk to each other using these numbers (us nerds call them IP addresses). Words and letters and names such as google.com or michaelhorowitz.com exist solely for the convenience of human beings. There is a huge system on the Internet called DNS that translates domain names into their corresponding numbers. Every time you ask for a website by name, your computer first contacts a DNS server machine to translate the name to the unique number. This happens so fast that you don't notice it.

The way this attack works is by changing the DNS server computers you use for translating names to numbers. Thus if www.citibank.com should translate to 1.2.3.4, the DNS computers of the bad guys would instead translate it to 88.55.11.99 (the numbers are just for illustration) which just so happens to be their identity theft website. Think of it as having a total stranger translating spoken languages. You can never be sure if the translation is accurate or not.

Adding to the danger of this attack is that it's undetectable. That is, anti-virus and anti-spyware software will not protect you. No files are put on your computer. In fact, no changes are made to your computer at all! Still worse, to review the settings in your router to see if anything has been changed, takes a computer nerd. Its too techie for normal people. As I said, this is as dangerous as dangerous gets.

Technically, this type of attack is known as pharming. Phishing refers to tricking a human being to go to the wrong website. Pharming involves tricking your computer to go to the wrong website.

The malicious program is written in a programming language called JavaScript. JavaScript programs live inside web pages and are executed by your web browser when you view a page. They are not executed by your operating system. This is not a Windows problem, it affects Macs and Linux too (any OS in fact).

You can disable JavaScript in your web browser, but it's not practical as so many web sites require it. You might however, consider using two web browsers and having JavaScript turned off in one of them and use this browser when visiting iffy websites. The Firefox browser has an optional NoScript extension that turns off JavaScript by default and then easily lets you enable it on a site by site basis. It's a very popular extension.

The following is a bit techie.

You can, and should, also protect your router by changing its IP address. This doesn't offer perfect protection, but does make it harder for the malicious software to find your router.

Another way to protect yourself is modifying the TCP/IP settings on your computer so that you don't get DNS services from your router. Let me explain:

Typically when your computer needs to translate a domain name to a number (IP address) it asks the router to do this and the router, in turn, talks to a dedicated DNS computer run by your ISP. A large organization may run their own DNS computers. The whole point here is that the bad guys can modify the router to talk to their DNS server.

Every ISP runs at least two dedicated DNS computers and they will be glad to provide their IP addresses (it's probably listed on the website of your ISP, this isn't a secret). My point here is to configure TCP/IP on your computer to talk directly to the DNS server of your ISP and avoid having the router acting as a middleman. Thus, even if the router is talking to a bad/compromised DNS server computer, you are not asking the router to do the DNS name-to-number translation.