Avatar

wop

wop@infosec.pub
Joined
52 posts • 51 comments

Blog: ittavern.com Feedback is appreciated

Direct message

Valid question. We’ve checked it multiple times, on the client and via monitoring that it is 10 Mbits. Thank you.

permalink
report
parent
reply

Not yet. Wouldn’t expect it tbh, but you’ll never know. How would you utilize Wirehuard for it? I’d like to hear more about it.

permalink
report
parent
reply

Good points! I’ll get access to test clients on both sites to do some testing. If I get the problem reproduced, I can take some packet captures without getting the client involved while monitoring the hardware. I’ll be smarter after that session.

Thank you!

permalink
report
parent
reply

Gotcha! - I thought Wireguard might has some logging features that could provide some insights. Thank you.

permalink
report
parent
reply

I haven’t had the chance to get a pcap yet. As soon as I get my fingers on the test clients, I’ll check them and additionally do testing with TCP and UDP transfers. I’ll let you know.

Just to clarify: this would be the limit for a single TCP connection and yes, could be the limit for this one download. This would not explain, why the rest of the location is affected if theoretically 90% of the bandwidth is still available, no? - Please correct me if I am wrong here.

permalink
report
parent
reply

Getting a pcap of another client could bring some insight, yeah.

SSH is used for the data transfer. Without knowing it at this moment, I’d assume scp or rsync. You mean whether all their internet traffic is routed through the active SSH session?

permalink
report
parent
reply

Will compare it as soon as I get my hands on the machine.

And yeah, we do tend to block ICMP over here too.

permalink
report
parent
reply

I am certain that we block ICMP on multiple FW in between. I could allow it temporary and check. Good suggestion.

permalink
report
parent
reply

You are right. Still an active policy that we have to work on.

permalink
report
parent
reply

I’ll keep that in mind

permalink
report
parent
reply