Re: packets duplicated *massively* on transmit.



Ian FREISLICH wrote:
Hi

I have two FreeBSD routers:

In two reasonably busy datacenters. We're seeing packet loss that
we traced to a packet ariving on the world-facing interface being
retransmitted approximately every 10 microseconds or so for 1 to 5
seconds out of the interface the client is on.

Someone has responded in private mail, but re-reading this it's
possible that I didn't explain the situation too well.

One packet arrives on the uplink interface. This packet is then
repeated between 60000 and 1500000 times out of the other interface
to the exclusion of all other traffic. It doesn't do this for every
packet, just once every 500000 or so.

Ian

--
Ian Freislich
_______________________________________________
freebsd-current@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-current
To unsubscribe, send any mail to "freebsd-current-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • RE: Intrusion Prevention requirements document
    ... The tools consider one interface as "client" and other ... Packet 1 is first sent out on client interface. ... > my previous company was Blade Software where I developed IDS Informer ... Up to 75% of cyber attacks are launched on shopping carts, ...
    (Pen-Test)
  • Re: Pix 515 VLAN NAT0 issues
    ... that ACL will be exempt from NAT. ... the packet at the time the PIX receives the packet. ... ACL applied to an inside interface would have the internal IPs as ... accepted as having a translation and satisfying the security policies. ...
    (comp.dcom.sys.cisco)
  • [NEWS] Ascends Undocumented Protocol Allows Unauthorized Modifications
    ... TAOS Operating System provides an easy to use and support interface. ... By sending a crafted UDP packet to the devices UDP discard port, ... 06/29/02 Initial Notification *Note-Initial notification by phenoelit ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
    (Securiteam)
  • RE: Intrusion Prevention requirements document
    ... The tools consider one interface as "client" and other ... Packet 1 is first sent out on client interface. ... > The product uses two network cards and so the library of over 700 ... > my previous company was Blade Software where I developed IDS Informer ...
    (Focus-IDS)
  • Re: Nmap questions concering my router
    ... First - there is no intelligence in the interface. ... it sees a packet addressed to it (first 6 bytes of the Ethernet packet ... addressed to hardware address 01:00:5E:* and pass them to the data bus ... network, and only gets secure administrative traffic. ...
    (comp.security.firewalls)