All of lore.kernel.org
 help / color / mirror / Atom feed
From: andre.correa@pobox.com
To: Cedric Blancher <blancher@cartel-securite.fr>
Cc: netfilter@lists.netfilter.org
Subject: Re[2]: Too many ARP entries and Re: sendto: No buffer space available
Date: Tue, 3 Dec 2002 12:27:24 -0200	[thread overview]
Message-ID: <875890239.20021203122724@pobox.com> (raw)
In-Reply-To: <1038920934.8888.4.camel@elendil.intranet.cartel-securite.net>


Hi again, looking at TCPDump I see this wierd traffic:

root@linuxbox:~# tcpdump -i eth1 | grep arp
tcpdump: listening on eth1
Dec  3 11:16:52 linuxbox kernel: device eth1 entered promiscuous mode
11:17:03.059629 arp who-has 64.12.163.212 tell linuxbox
11:17:03.060569 arp reply 64.12.163.212 is-at 0:2:b9:1d:db:41
11:17:07.669629 arp who-has 172.18.1.218 tell linuxbox
11:17:07.670610 arp reply 172.18.1.218 is-at 0:2:b9:1d:db:41
11:17:07.839630 arp who-has 64.12.27.135 tell linuxbox
11:17:07.840544 arp reply 64.12.27.135 is-at 0:2:b9:1d:db:41
11:17:07.850840 arp who-has baym-cs17.msgr.hotmail.com tell linuxbox
11:17:07.852219 arp reply baym-cs17.msgr.hotmail.com is-at 0:2:b9:1d:db:41
11:17:09.888162 arp who-has 207.46.106.80 tell linuxbox
11:17:09.889078 arp reply 207.46.106.80 is-at 0:2:b9:1d:db:41
11:17:10.389189 arp who-has 204.152.184.64 tell linuxbox
11:17:10.390134 arp reply 204.152.184.64 is-at 0:2:b9:1d:db:41
11:17:10.640043 arp who-has 200.225.157.104 tell linuxbox
11:17:10.640967 arp reply 200.225.157.104 is-at 0:2:b9:1d:db:41
11:17:10.689240 arp who-has 200.225.157.165 tell linuxbox
11:17:10.690768 arp reply 200.225.157.165 is-at 0:2:b9:1d:db:41
11:17:10.893170 arp who-has 200.225.157.163 tell linuxbox
11:17:10.894088 arp reply 200.225.157.163 is-at 0:2:b9:1d:db:41
11:17:10.980746 arp who-has 200.225.157.167 tell linuxbox
11:17:10.981714 arp reply 200.225.157.167 is-at 0:2:b9:1d:db:41
11:17:11.504255 arp who-has a.gtld-servers.net tell linuxbox
11:17:11.505926 arp reply a.gtld-servers.net is-at 0:2:b9:1d:db:41

2183 packets received by filter
0 packets dropped by kernel

We   see   my   linux  box  asking  for MAC addresses of hosts outside
its "local" network and my gateway, a Cisco 2621 answering those
broadcasts with its own MAC address.

For  what  I know, both are doing wrong. My box is not supposed to ask
for those MACs and the Cisco is not supposed to answer.

Does anybody have seen these before or have any ideas what would cause
it?

tks in advance.

Andre



On 03/12/02, Cedric Blancher wrote:
CB> Le lun 02/12/2002 à 21:28, andre.correa@pobox.com a écrit :
>> But  there  is  still a question for me. Looking at my arp table, I
>> see that there are =~ 150 entries, seconds passing and more entries
>> coming, 20 seconds after I can have =~1100, it goes on until it reachs
>> =~2200  entries,  then it goes back to the =~100 and starts over again.

CB> Wierd...

>> I  have  less  then  50  NAT users. Is it normal to have some many ARP
>> entries with this variation? Looking the ARP table I see my "Internet"
>> interface with lots of entries, with internet host IP addresses and my
>> gateway's NIC MAC address.
>> Isn't ARP supposed to keep entries just to local network systems?

CB> Yes it is.
CB> ARP is supposed to keep track of IP/MAC associations for network
CB> directly routed to interface, i.e. directly connected, aka local LANs.

>> Is it all normal? And if so, how big can gc_threash[1,2,3] be?

CB> It is not normal. You should monitor ARP traffic on your network using
CB> arpwatch (see Freshmeat, available as .deb, .rpm too) to see if someone
CB> would be playing ARP cache poisoning (see http://www.arp-sk.org/).



  parent reply	other threads:[~2002-12-03 14:27 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2002-12-02 13:16 sendto: No buffer space available andre.correa
2002-12-02 14:33 ` Bob Keyes
2002-12-02 14:46   ` Re[2]: " andre.correa
2002-12-02 20:28 ` Too many ARP entries and " andre.correa
2002-12-03 13:08   ` Cedric Blancher
2002-12-03 13:27     ` Nick Drage
2002-12-03 14:27     ` andre.correa [this message]
2002-12-03 17:54       ` Nick Drage
2002-12-04  3:09         ` Paul Frieden
2002-12-04 15:23       ` Ard van Breemen

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=875890239.20021203122724@pobox.com \
    --to=andre.correa@pobox.com \
    --cc=andre.docena@pobox.com \
    --cc=blancher@cartel-securite.fr \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.