OpenVZ Forum


Home » General » Support » Dropped packet, source wrong in syslog
Dropped packet, source wrong in syslog [message #16445] Thu, 06 September 2007 16:43 Go to next message
Alex Prinsier is currently offline  Alex Prinsier
Messages: 16
Registered: January 2007
Junior Member
I regularly see messages like these in my syslog, anyone knows when they occur? I'm not running any packet sniffer, packet forging, scanner or such related tool. So I wonder where these packets come from. (ve 201 has ip 10.1.1.2)

Dropped packet, source wrong veid=201 src-IP=10.1.1.5 dst-IP=10.1.1.1
Re: Dropped packet, source wrong in syslog [message #16461 is a reply to message #16445] Fri, 07 September 2007 09:27 Go to previous messageGo to next message
khorenko is currently offline  khorenko
Messages: 533
Registered: January 2006
Location: Moscow, Russia
Senior Member
Well, due to security reasons venet has a special feature - it doesn't allow a VE to send a packet with source IP different from the VE IP (one of).
This is exactly what happens on your node: VE201 tries to send a packet with IP which is not assigned to the VE. Such a packet is dropped.


If your problem is solved - please, report it!
It's even more important than reporting the problem itself...
Re: Dropped packet, source wrong in syslog [message #20149 is a reply to message #16461] Wed, 12 September 2007 15:12 Go to previous messageGo to next message
Alex Prinsier is currently offline  Alex Prinsier
Messages: 16
Registered: January 2007
Junior Member
Well yes, that's what I suspected. But all that's running there is postfix and syslog-ng which reports to a syslog-ng server on 10.1.1.5 (VE 205). I wonder what app sent out that packet. Is there a way to find out? I can hardly believe it to be a bug in postfix or syslog-ng.
Re: Dropped packet, source wrong in syslog [message #20187 is a reply to message #20149] Thu, 13 September 2007 06:32 Go to previous message
khorenko is currently offline  khorenko
Messages: 533
Registered: January 2006
Location: Moscow, Russia
Senior Member
Well, i personally believe that this is a bug in an application, but we can check. You said that you see these messages periodically - can you run tcpdumps inside both VEs 201 and 205 and wait till a new message is logged (or better - several messages)? (it's better to save the tcpdump's output to a file of course)
After that you/we can check the tcpdump's logs for the packet with incorrect source address.

Hope to hear from you the result of the experiment, it will be great if you turn out to be right and we can fix one more bug in kernel with your help. Smile


If your problem is solved - please, report it!
It's even more important than reporting the problem itself...
Previous Topic: *SOLVED* On a raid1 system, when disk IO is high, The system might become "freeze"...
Next Topic: i have problem with apf and csf any firewall
Goto Forum:
  


Current Time: Wed Nov 29 04:33:28 GMT 2023

Total time taken to generate the page: 0.02879 seconds