DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Predictable TCP Initial Sequence Numbers
- haywardi
- Topic Author
- Offline
- Member
Less
More
- Posts: 187
- Thank yous received: 0
03 Feb 2016 20:33 #85263
by haywardi
Iain
Replied by haywardi on topic Re: Predictable TCP Initial Sequence Numbers
Completely agree lol.
But that said a random number I would expect to go up and down, well randomly. But it doesn't, it increments each time... And as the description says it may be linked to the time and that increments it looks to me like a there a link..
But that said a random number I would expect to go up and down, well randomly. But it doesn't, it increments each time... And as the description says it may be linked to the time and that increments it looks to me like a there a link..
Iain
Please Log in or Create an account to join the conversation.
- haywardi
- Topic Author
- Offline
- Member
Less
More
- Posts: 187
- Thank yous received: 0
04 Feb 2016 10:46 #85268
by haywardi
Iain
Replied by haywardi on topic Re: Predictable TCP Initial Sequence Numbers
Another interesting thought.
Back in December I received my first compliance scan results. I've just re-checked the report, it did highlight a number of weaknesses mostly related to SSL and crucially IT DID NOT HIGHLIGHT THIS FAULT.
Now I'm wondering if the upgrade to 3.6.8.2 introduced this fault (a regression bug?). I did the upgrade thinking a needed to be on the latest OS level to achieve compliance..
Can't take the router off line until the weekend to confirm my suspicion, but it's very odd it didn't appear on the December report.
Iain
Back in December I received my first compliance scan results. I've just re-checked the report, it did highlight a number of weaknesses mostly related to SSL and crucially IT DID NOT HIGHLIGHT THIS FAULT.
Now I'm wondering if the upgrade to 3.6.8.2 introduced this fault (a regression bug?). I did the upgrade thinking a needed to be on the latest OS level to achieve compliance..
Can't take the router off line until the weekend to confirm my suspicion, but it's very odd it didn't appear on the December report.
Iain
Iain
Please Log in or Create an account to join the conversation.
- haywardi
- Topic Author
- Offline
- Member
Less
More
- Posts: 187
- Thank yous received: 0
06 Feb 2016 15:26 #85291
by haywardi
Iain
Replied by haywardi on topic Re: Predictable TCP Initial Sequence Numbers
A further update.
Reset the router back to 3.6.6.1.
Hay presto! No predictable TCP initial sequence numbers and more importantly I now have PCI/DSS compliance on my network.
Think you have a regression bug, but sorry for being a bit grumpy!
Iain
Reset the router back to 3.6.6.1.
Hay presto! No predictable TCP initial sequence numbers and more importantly I now have PCI/DSS compliance on my network.
Think you have a regression bug, but sorry for being a bit grumpy!
Iain
Iain
Please Log in or Create an account to join the conversation.
- haywardi
- Topic Author
- Offline
- Member
Less
More
- Posts: 187
- Thank yous received: 0
18 Feb 2016 16:06 #85387
by haywardi
Iain
Replied by haywardi on topic Re: Predictable TCP Initial Sequence Numbers
Sorry to resurrect this post, but thought I would like to add that I purchased a 2925 running 3.8.1 .
Unfortunately this problem is present on the 2925!!!!
I will report it to Draytek support officially, but Draytek what are you doing!
Guess the 2925 will be going back now!
Iain
Unfortunately this problem is present on the 2925!!!!
I will report it to Draytek support officially, but Draytek what are you doing!
Guess the 2925 will be going back now!
Iain
Iain
Please Log in or Create an account to join the conversation.
- haywardi
- Topic Author
- Offline
- Member
Less
More
- Posts: 187
- Thank yous received: 0
18 Feb 2016 16:07 #85388
by haywardi
Iain
Replied by haywardi on topic Re: Predictable TCP Initial Sequence Numbers
Oops sorry, I mis-typed I'm running 3.8.2!
Iain
Please Log in or Create an account to join the conversation.
- admin
- Offline
- Site Admin
Less
More
- Posts: 1723
- Thank yous received: 0
18 Feb 2016 18:55 #85390
by admin
Seems like a bit of an over-reaction. If it's a genuine problem, they'd likely fix it...
Forum Administrator
Replied by admin on topic Re: Predictable TCP Initial Sequence Numbers
Guess the 2925 will be going back now!haywardi wrote:
Seems like a bit of an over-reaction. If it's a genuine problem, they'd likely fix it...
Forum Administrator
Please Log in or Create an account to join the conversation.
Moderators: Chris
Copyright © 2025 DrayTek