Tenda MW6 mesh is talking to baidu - how do I evesdrop with a linux router?Guest wifi mode on a secondary...
Boss asked me to sign a resignation paper without a date on it along with my new contract
How to politely refuse in-office gym instructor for steroids and protein
Why don't key signatures indicate the tonic?
Removing whitespace between consecutive numbers
Potential client has a problematic employee I can't work with
Why did the villain in the first Men in Black movie care about Earth's Cockroaches?
Why zero tolerance on nudity in space?
In Linux what happens if 1000 files in a directory are moved to another location while another 300 files were added to the source directory?
How do you catch Smeargle in Pokemon Go?
What is the difference between rolling more dice versus fewer dice?
Is there a verb that means to inject with poison?
Count repetitions of an array
Looking for a specific 6502 Assembler
What happens when the wearer of a Shield of Missile Attraction is behind total cover?
Is there a lava-breathing lizard creature (that could be worshipped by a cult) in 5e?
Bash script to truncate subject line of incoming email
Explanation of a regular pattern only occuring for prime numbers
How to assess the long-term stability of a college as part of a job search
After checking in online, how do I know whether I need to go show my passport at airport check-in?
Globe trotting Grandpa. Where is he going next?
What is the wife of a henpecked husband called?
Is there a defined priority for pattern matching?
How much mayhem could I cause as a fish?
How to not let the Identify spell spoil everything?
Tenda MW6 mesh is talking to baidu - how do I evesdrop with a linux router?
Guest wifi mode on a secondary routerDD-WRT: How To Do Multiple APs on Wired Network?Double Port Forwarding with two routers on the same networkDD-WRTs Repeater Bridge Mode and additional virtual interfaces with own DHCP rangeShould my router bandwidth log “see” traffic between two devices on the same switch?Cannot connect to second router wirelessHow to setup a Zyxel router in Bridged mode?Slow speeds with using old router as a switchISP modem/router, how do I enable Bridged Mode and use my own router?Shall I give my secondary router a reserved IP through DHCP or ARP?
I recently picked up a set of tenda MW6 mesh units - I'm running this in "bridged" mode, since that's the only option that turns off their dhcp server. The primary mesh unit connected to a DIY linux router (ubuntu, with firewalld. The full setup is here) - which allows me to run a few more interesting tools to monitor my traffic. The linux router provides DHCP and DNS and has 3 ports bridged together to a single interface, and the primary mesh unit is on one of these ports. I can apparently run tcpdump and pick up traffic going through the mesh units
I'm running the mesh units in bridged mode, if that matters, and the backhaul to the secondaries are over wireless. The tendas are managed through a phone application but its local, with no cloud accounts set up.
Router - Runs ubuntu + firewalld
192.168.1.1
+
|
|
|
v
Primary Mesh Node (Tenda MW6) 192.168.1.99
+
Secondary | Secondary
192.168.1.91 <-----+-----> 192.168.1.87
I noticed using iftop that the devices talk to 45.113.192.102 - an IP that seems to belong to a chinese search engine called baidu, and tcpdump indicates that all 3 nodes are connecting to the IP over http
01:43:00.987943 IP 192.168.1.99.34783 > 45.113.192.102.http: Flags [F.], seq 1, ack 1, win 913, length 0
is an example of the output of tcpdump at my main router. At this point - though I'm stuck. Is there any way I can check what the traffic is?
wireless-networking router security
add a comment |
I recently picked up a set of tenda MW6 mesh units - I'm running this in "bridged" mode, since that's the only option that turns off their dhcp server. The primary mesh unit connected to a DIY linux router (ubuntu, with firewalld. The full setup is here) - which allows me to run a few more interesting tools to monitor my traffic. The linux router provides DHCP and DNS and has 3 ports bridged together to a single interface, and the primary mesh unit is on one of these ports. I can apparently run tcpdump and pick up traffic going through the mesh units
I'm running the mesh units in bridged mode, if that matters, and the backhaul to the secondaries are over wireless. The tendas are managed through a phone application but its local, with no cloud accounts set up.
Router - Runs ubuntu + firewalld
192.168.1.1
+
|
|
|
v
Primary Mesh Node (Tenda MW6) 192.168.1.99
+
Secondary | Secondary
192.168.1.91 <-----+-----> 192.168.1.87
I noticed using iftop that the devices talk to 45.113.192.102 - an IP that seems to belong to a chinese search engine called baidu, and tcpdump indicates that all 3 nodes are connecting to the IP over http
01:43:00.987943 IP 192.168.1.99.34783 > 45.113.192.102.http: Flags [F.], seq 1, ack 1, win 913, length 0
is an example of the output of tcpdump at my main router. At this point - though I'm stuck. Is there any way I can check what the traffic is?
wireless-networking router security
add a comment |
I recently picked up a set of tenda MW6 mesh units - I'm running this in "bridged" mode, since that's the only option that turns off their dhcp server. The primary mesh unit connected to a DIY linux router (ubuntu, with firewalld. The full setup is here) - which allows me to run a few more interesting tools to monitor my traffic. The linux router provides DHCP and DNS and has 3 ports bridged together to a single interface, and the primary mesh unit is on one of these ports. I can apparently run tcpdump and pick up traffic going through the mesh units
I'm running the mesh units in bridged mode, if that matters, and the backhaul to the secondaries are over wireless. The tendas are managed through a phone application but its local, with no cloud accounts set up.
Router - Runs ubuntu + firewalld
192.168.1.1
+
|
|
|
v
Primary Mesh Node (Tenda MW6) 192.168.1.99
+
Secondary | Secondary
192.168.1.91 <-----+-----> 192.168.1.87
I noticed using iftop that the devices talk to 45.113.192.102 - an IP that seems to belong to a chinese search engine called baidu, and tcpdump indicates that all 3 nodes are connecting to the IP over http
01:43:00.987943 IP 192.168.1.99.34783 > 45.113.192.102.http: Flags [F.], seq 1, ack 1, win 913, length 0
is an example of the output of tcpdump at my main router. At this point - though I'm stuck. Is there any way I can check what the traffic is?
wireless-networking router security
I recently picked up a set of tenda MW6 mesh units - I'm running this in "bridged" mode, since that's the only option that turns off their dhcp server. The primary mesh unit connected to a DIY linux router (ubuntu, with firewalld. The full setup is here) - which allows me to run a few more interesting tools to monitor my traffic. The linux router provides DHCP and DNS and has 3 ports bridged together to a single interface, and the primary mesh unit is on one of these ports. I can apparently run tcpdump and pick up traffic going through the mesh units
I'm running the mesh units in bridged mode, if that matters, and the backhaul to the secondaries are over wireless. The tendas are managed through a phone application but its local, with no cloud accounts set up.
Router - Runs ubuntu + firewalld
192.168.1.1
+
|
|
|
v
Primary Mesh Node (Tenda MW6) 192.168.1.99
+
Secondary | Secondary
192.168.1.91 <-----+-----> 192.168.1.87
I noticed using iftop that the devices talk to 45.113.192.102 - an IP that seems to belong to a chinese search engine called baidu, and tcpdump indicates that all 3 nodes are connecting to the IP over http
01:43:00.987943 IP 192.168.1.99.34783 > 45.113.192.102.http: Flags [F.], seq 1, ack 1, win 913, length 0
is an example of the output of tcpdump at my main router. At this point - though I'm stuck. Is there any way I can check what the traffic is?
wireless-networking router security
wireless-networking router security
asked 17 mins ago
Journeyman Geek♦Journeyman Geek
112k44217371
112k44217371
add a comment |
add a comment |
0
active
oldest
votes
Your Answer
StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "3"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});
function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});
}
});
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f1409745%2ftenda-mw6-mesh-is-talking-to-baidu-how-do-i-evesdrop-with-a-linux-router%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
0
active
oldest
votes
0
active
oldest
votes
active
oldest
votes
active
oldest
votes
Thanks for contributing an answer to Super User!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f1409745%2ftenda-mw6-mesh-is-talking-to-baidu-how-do-i-evesdrop-with-a-linux-router%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown