Cisco Patch Quells Duke's Apple iPhone Storms

By John Cox
Wed, July 25, 2007

Network WorldCisco has just released a new security advisory that details what caused the address storms that recently afflicted Duke University's wireless net.

The advisory, posted on the company's website, says that Cisco's wireless LAN controllers have "multiple vulnerabilities in the handling of Address Resolution Protocol (ARP) packets." These vulnerabilities "could result in a denial of service (DoS) in certain environments." The vendor is offering free software to patch this problem, and notes that "there are workarounds to mitigate the effects of these vulnerabilities."

In keeping with Cisco's standard format, the advisory makes no reference to the events at Duke, which were first reported a week ago. At the time, intermittent floods or storms of ARP requests were taking 20 to 30 WLAN access points offline for 10 to 15 minutes. The events involved the newly released Apple iPhone.

But a Cisco spokesman confirmed that the advisory deals with the problem uncovered at Duke. "To date, we have not seen widespread issues relating to Apple iPhone across our customers' networks," the spokesman wrote in an e-mail response.

The baffling problem, occurring at least nine times at Duke over about a week, triggered a wave of reader speculation, rants and recommendations on Networkworld.com and other Internet tech sites.

The advisory finally makes it clear that the iPhone simply triggered the ARP storms that were made possible by the controller vulnerabilities. Any other wireless client device, moving from one subnet to another, apparently could have done the same thing.

According to the advisory, the vulnerabilities are found in versions 4.1, 4.0, and 3.2 and earlier of the company's Wireless LAN Controller software. Affected products include the 4100 and 4400 series of controllers, the earlier Cisco-Airespace 4000 series controller (introduced shortly after Cisco acquired Airespace), the Catalyst 6500 series Wireless Services Module (WiSM, a single-board version of the controller), and the Catalyst 3750 Integrated Wireless LAN Controller.

Many other products are immune to these vulnerabilities, according to Cisco, including the 2000 and 2100 series controllers, various standalone access points, and the 3800, 2800 and 1800 series of Integrated Services Routers.

The identified vulnerabilities relate to a unicast ARP request that in certain circumstances can be flooded on the LAN links between a group of WLAN controllers (Cisco calls this a "mobility group").

The advisory notes that IP Version 4 hosts use a method, specified in the IETF standard RFC 4436, to detect if they have reattached to a network to which they had previously been attached. If so, the host may not have to request a new DHCP address lease if the current lease is still active, according to the advisory. To determine this reattachment, the host sends a unicast ARP request to the default gateway that it had previously used.

Continue Reading

This paper covers power utilization, intelligent power management and industry best practices for energy efficiency. Extreme Networks® takes a lifecycle approach to power efficiency, management and recycling, offering savings to our customers and promoting a greener world.
Virtualization and cloud are driving new requirements for data center network performance, VM support, automation and simplified orchestration. This paper outlines Extreme Networks® open fabric approach to high speed, low latency networks for modern data centers.
The evolution of the network to provide the intelligence needed to address user, device and application mobility is underway. In this white paper, Extreme Networks® outlines the five phases required to bring mobility into the network.
The McAfee virtual patching solution provides a layered approach to security risk management, while adding the ability to apply a virtual patching strategy to your existing change-management process.
Learn more about Gartner's evaluation of network IPS that places McAfee in the leaders' quadrant. Deep inspection network-based intrusion prevention continues to be a due-diligence security control.
IP networks are growing at an exponential rate thanks to virtualization, mobile devices and IP v6. But IT departments are under budget constraints and skilled staff is becoming scarce. The solution..
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and enterprise campus network infrastructures for the Cloud, and identify ways to better allocate network resources, reduce operating costs and improve application performance.
Learn how Gartner's criteria for next generation IPS helps organizations achieve effective threat prevention despite changes in network communications, new applications, and changes in the threat landscape.
Today's networks are under attack. To build a better network, you've got to understand the stresses that today's networks are under due to mobility, virtualization and cloud computing.
As greater numbers of datacenter servers transition from the physical to the virtual world, the components of virtualization success come to the fore. What scores of organizations have discovered is that success is derived from an optimal pairing of the right software platform with the right hardware platform.
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn about VMware customer, Navicure, and their experiences testing and evaluating the recovery manager, their progress in implementing it in their environment and their advice other customers considering using vCenter.
Many enterprises have discovered that the use of virtualization to support desktop workloads creates a range of significant benefits. These benefits include price efficiencies, improved IT management and greater agility and choice for end users.

This VMware sponsored webcast with IDC will provide both quantitative measurement of the business value -- defined as the expected ROI -- and qualitative analysis associated with the use of VMware View™. IDC will also provide an analysis of the View Composer and ThinApp™ features of VMware View, including the business value of these solutions and an overview of how they work.

Attend this webcast to learn about:
- Challenges and barriers that might impede the adoption of desktop virtualization
- Navigating roadblocks to facilitate a strategic implementation
- Optimizing qualitative and quantitative benefits to IT and your business
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Sponsored Links
Resource Center