Jump to content
Sign in to follow this  
FerMng

Ping in IPv6 (ICMP Echo request) Fail by the adition of "Hop-by-Hop" Option

Recommended Posts

Hello, we need to implement IPv6 in our Company. Actually we have a issue with the ICMP protocol IPv6, we haven`t ping response from internet host in IPv6. In the forum we saw that we have to request private patch 1920 for that particular case for Windows 8 and 8.1 and the patch 3020 for Windows 10. Thats patchs resolve this problems of ping but.. ¿what happen with KES 11 and Windows 10?.

 

I tried to uninstall KES 11 and I have ping to www.facebook.com [2a03:2880:f104:83:face:b00c:0:25de] but When I install KES 11 RC 11.0.0.6485 AES256 the ping fail.

 

Will Kasperksy include the patch for alow ICMP IPv6 in the new version KES 11?.

 

Share this post


Link to post

Hello. 

Could you ping IPv6 link-local  addresses ?

Share this post


Link to post
hace 9 horas, Evgeny_E dijo:

Hello. 

Could you ping IPv6 link-local  addresses ?

HI, yes!, I can ping to link-local. The Hop by Hop options header include information for the routers, if the packet is process by the router it discart it by that information. Thats is because i can ping to link-local, that ping don´t go to diferent network.

Share this post


Link to post

Hello. 

Please collect the following information during ICMP requests :

  • KES trace logs, after enabling  tracing in local interface make sure to restart Endpoint Security 11.
  • Wireshark logs. 

Also upload:

  • Configuration or policy export
  • Full GSI report
  • Information about  remote global unicast address 

 

 

Share this post


Link to post

I can`t upload files for more of 4MB and the GSI its up 5,4MBs. Can I open a case in the Kaspersky CompanyAccount for this release candidate KES 11?

Share this post


Link to post

This is the capture of whireshark "pinging" to google IPV6. That is the aditional header options "Hop-by-Hop" added for the Kasperksy KES11 (like KES10 withouth patch 3020). When the router intent to forward to Internet it drop the packet.

wiresharkwithKasperksy.JPG

Share this post


Link to post

Today curiously there have a problem with Google IPv6 on our Carrier, but I did the test with Facebook.

 

I attach .doc with the test:

- Without Antivirus i get icmp response from IPv6 on www.Facebook.com

- With KES 11 (active or disabled ) the icmp fail because the icmp request include a Next Header added with the famously Hop-by-Hop Option that routers don´t likes to forward.

kaspersky11-icmpv6.docx

Share this post


Link to post

Hello.

We will need requested data to submit a request to developers team. 

 

Share this post


Link to post

HI! Evgeny_E@ I`ll send you a private message with the information requested.

Share this post


Link to post

Please send information to KLCentralSupport and don't forget to supply detailed experiment description.

Share this post


Link to post

Hello.

I have submitted an issue to developers team. 

Issue number 2673361

Share this post


Link to post
On 26.03.2018 at 12:37 PM, FerMng said:

i just do it. Thanks.

Issue solved in private fix pf5012 for the release version of KES 11. After installing the release version, you can request the patch via CompanyAccount by creating an incident.

Thank you.

Share this post


Link to post
Sign in to follow this  

×

Important Information

We use cookies to make your experience of our websites better. By using and further navigating this website you accept this. Detailed information about the use of cookies on this website is available by clicking on more information.