From: "Mark E. Donaldson" <markee@bandwidthco.com>
To: 'Carlos Fernandez Sanz' <cfs-netfilter@nisupu.com>,
'netfilter' <netfilter@lists.netfilter.org>
Subject: RE: Strange logs...
Date: Sun, 11 Jan 2004 13:49:38 -0800 [thread overview]
Message-ID: <200401112149.i0BLnXHu000956@server5.bandwidthco.com> (raw)
In-Reply-To: <004001c3d846$e4e85e90$1530a8c0@HUSH>
If both the Linux Box and the Windows box on the same standard subnet of
192.168.20.0/24, and they are connected via a switch, then the packets
should never need to go through the router in the first place. This tells me
the switch is either configured wrong, or is faulty. Question: Are you
dropping "spoofed IP's" on your router using the NAT table?
-----Original Message-----
From: netfilter-admin@lists.netfilter.org
[mailto:netfilter-admin@lists.netfilter.org] On Behalf Of Carlos Fernandez
Sanz
Sent: Sunday, January 11, 2004 5:29 AM
To: netfilter
Subject: Re: Strange logs...
> > How reliable is ethereal? I mean, does it see packets as they come
> > from
the
> > wire or after they have been touched by netfilter?
>
> Ethereal and tcpdump will both see packets off the wire before they get to
> netfilter. Remember that these packet capturing programs and not
After leaving it working for some more minutes, I started seeing normal
traffic being logged as well. Packets show up in eth1 (internet interface)
both in the logs and ethereal (there's a 100% match). Now, how are the linux
device (eth1) linked to the physical device (NIC) related?
I have to say that if I unplug any of the two cables (the one between the
linux and the switch or the one between the linux and the router) strange
things happen. So I'm really starting to believe that the packet does come
from the wire physically.... no matter how impossible that seems.
As I finished writing that I tried to ping from the windows box to the linux
box and both cables must be connected for ping responses to arrive. This
happens even with all the iptables tables flushed (ie firewall down; no
rules, and ACCEPT as policies for both input and policies).
> > (still, is that possible? How could a packet generated by the
> > windows
box,
> > which isn't connected to eth1, end up there?).
>
> That's the one bit I can't think of an explanation for. You don't have
> anything exotic like bridging or vlans enabled in your kernel do you?
Nothing (that I'm aware of, anyway). But this is starting to look more like
a hardware issue to me. Definitely not related to the wiring, but maybe
there's some kind of conflict between my NICs I haven't spotted yet.... so
in case it helps:
Bus 2, device 11, function 0:
Ethernet controller: 3Com Corporation 3c905C-TX/TX-M [Tornado] (rev 48).
IRQ 9.
Master Capable. Latency=32. Min Gnt=10.Max Lat=10.
I/O at 0xd800 [0xd87f].
Non-prefetchable 32 bit memory at 0xf4000000 [0xf400007f].
Bus 2, device 14, function 0:
Ethernet controller: 3Com Corporation 3c905C-TX/TX-M [Tornado] (#2) (rev
48).
IRQ 3.
Master Capable. Latency=32. Min Gnt=10.Max Lat=10.
I/O at 0x8800 [0x887f].
Non-prefetchable 32 bit memory at 0xf3800000 [0xf380007f].
Thanks for helping out :-)
next prev parent reply other threads:[~2004-01-11 21:49 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-01-11 11:40 Strange logs Carlos Fernandez Sanz
2004-01-11 12:02 ` Antony Stone
2004-01-11 12:41 ` Carlos Fernandez Sanz
2004-01-11 12:51 ` Antony Stone
2004-01-11 13:29 ` Carlos Fernandez Sanz
2004-01-11 13:40 ` Antony Stone
2004-01-11 13:59 ` Carlos Fernandez Sanz
2004-01-11 14:09 ` Antony Stone
2004-01-11 15:34 ` Unknown, Alistair Tonner
2004-01-11 21:49 ` Mark E. Donaldson [this message]
2004-01-11 21:58 ` Antony Stone
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200401112149.i0BLnXHu000956@server5.bandwidthco.com \
--to=markee@bandwidthco.com \
--cc=cfs-netfilter@nisupu.com \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox