Networking Forums

Networking Forums > Computer Networking > Linux Networking > Lost packets - strange problem

Reply
Thread Tools Display Modes

Lost packets - strange problem

 
 
martin.ferrari@gmail.com
Guest
Posts: n/a

 
      03-27-2006, 06:21 PM
(x-posted in linux-net mailing list)

Hi!

I'm having a very strange problem. I have already tested a *lot* of
things before asking, and I still have no clue of wha't happening.

I have 6 linux boxes acting as firewalls/routers. They are using
similar configurations and netfilter rules since 4 years ago, when I
installed the first of these. Some of them route more than 10 Mbps
between interfaces, 50000+ connections tracked with netfilter, traffic
shaping, NAT, and stuff, and they don't even blink.

BUT, two of them started giving headaches, they doesn't have the highes
usage, but they lose packets (in any interface) up to 80%, sometimes
softirqd eats all the cpu, and you cannot even connect to the boxes.
This does not happen from the very first day, and not all the time!

The NICs are mostly 3c905*(a mix of them), also some e100 and 3c940
(sk98lin). The troublesome computers have 3c905 and 3c940, but I do
not find any pattern on hardware.

Also, the error count is 0 in the internet interface of the host which
fails the most.

I tried rewriting the rules, turning off traffic shaping, changing
NICs, then changing ALL the hardware (they have some very nice and fast
hardware now). I even migrated from debian woody with 2.4.x kernels to
debian sarge with 2.6.8 kernels and the problem is still the same. I
don't really know what to do.

I suspect that this could be triggered by some internet DoS attack, but
I didn't find anything special (I have already solved the recursion
problem with DNS servers). The 6 servers receive loads of dumb attacks
all the time.

Any help would be greatly appreciated!

PS: please, CC me, as I'm not subscribed.

--
Martín Ferrari

 
Reply With Quote
 
 
 
 
hackson.w
Guest
Posts: n/a

 
      03-28-2006, 03:58 AM
I think you can use some tools,like tcpdump/ethereal, to grap some
packages --espesially the packages that go through the 2 servers.
Maybe you can find some info about your trouble.

Good luck!

 
Reply With Quote
 
hackson.w
Guest
Posts: n/a

 
      03-28-2006, 04:00 AM
I think you can use some tools,like tcpdump/ethereal, to grasp some
packages --espesially the packages that go through the 2 servers.
Maybe you can find some info about your trouble.

Good luck!

 
Reply With Quote
 
=?iso-8859-1?q?Mart=EDn_Ferrari?=
Guest
Posts: n/a

 
      03-28-2006, 03:22 PM
Uhm. I have already tried that But, when you have so much traffic
those tools aren't so helpful. I have plenty of attacks, both in the
well behaving machines and in the other two.

I'm thinking in something much more low-level. Maybe someone with
knowledge in kernel internals could give me a clue....

 
Reply With Quote
 
king
Guest
Posts: n/a

 
      03-28-2006, 04:01 PM
Do you even try using "ntop" to capture all traffic that flow throght
the firewall. It can provide many valuable information of your network
flow. Good luck
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
When did I lost packets? Spoon Linux Networking 5 05-04-2006 07:45 AM
packets being lost in ip_layer seossenk Linux Networking 0 11-11-2005 02:51 AM
wlan not working at all (lost packets) Jochen Demmer Linux Networking 1 04-27-2005 12:21 AM
ppp lost packets - 16850 uart Al Linux Networking 0 07-26-2004 06:16 AM
DI624 strange behavior/lost connection Robert Desel Wireless Internet 1 01-31-2004 04:45 AM



1 2 3 4 5 6 7 8 9 10 11