Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #263771 > unrolled thread
| Started by | Nicolas George <george@nsup.org> |
|---|---|
| First post | 2023-11-22 11:40 +0100 |
| Last post | 2023-11-22 12:10 +0100 |
| Articles | 7 — 2 participants |
Back to article view | Back to linux.debian.user
Weird MAC address Nicolas George <george@nsup.org> - 2023-11-22 11:40 +0100
Re: Weird MAC address Marco Moock <mm@dorfdsl.de> - 2023-11-22 12:00 +0100
Re: Weird MAC address Marco Moock <mm@dorfdsl.de> - 2023-11-22 12:00 +0100
Re: Weird MAC address Nicolas George <george@nsup.org> - 2023-11-22 12:10 +0100
Re: Weird MAC address Marco Moock <mm@dorfdsl.de> - 2023-11-22 12:20 +0100
Re: Weird MAC address Nicolas George <george@nsup.org> - 2023-11-22 12:00 +0100
Re: Weird MAC address Marco Moock <mm@dorfdsl.de> - 2023-11-22 12:10 +0100
| From | Nicolas George <george@nsup.org> |
|---|---|
| Date | 2023-11-22 11:40 +0100 |
| Subject | Weird MAC address |
| Message-ID | <HCSOd-7cg4-7@gated-at.bofh.it> |
Hi. Since last we have four MAC addresses in the ARP table of a server that should not be there: $ ip route default via XXX.XXX.98.254 dev eth0 onlink XXX.XXX.96.0/22 dev eth0 proto kernel scope link src XXX.XXX.98.94 But: $ ip neigh | grep -v 'XXX.XXX.9[6789]' XXX.XXX.103.161 dev eth0 lladdr YY:YY:YY:YY:YY:YY<STALE XXX.XXX.103.189 dev eth0 lladdr YY:YY:YY:YY:YY:YY STALE XXX.XXX.100.76 dev eth0 lladdr ZZ:ZZ:ZZ:ZZ:ZZ:ZZ STALE XXX.XXX.100.86 dev eth0 lladdr ZZ:ZZ:ZZ:ZZ:ZZ:ZZ STALE $ arp -a | grep -v 'XXX.XXX.9[6789]' ? (XXX.XXX.103.161) at YY:YY:YY:YY:YY:YY [ether] on eth0 ? (XXX.XXX.103.189) at YY:YY:YY:YY:YY:YY [ether] on eth0 XXXX.XX.XXX.XX (XXX.XXX.100.76) at ZZ:ZZ:ZZ:ZZ:ZZ:ZZ [ether] on eth0 XXXX.XX.XXX.XX (XXX.XXX.100.86) at ZZ:ZZ:ZZ:ZZ:ZZ:ZZ [ether] on eth0 As you can see, the server is on the …96.0/22 subnet, i.e. …96-…99, but it sees MAC addresses on the 100 and 103 networks. I ran tcpdump for some time and saw no ARP packet with these addresses. And they will not go away by themselves like the rest of the ARP tables. Does anybody have an inkling about why a Linux kernel would register neighbors like that? Regards, -- Nicolas George
[toc] | [next] | [standalone]
| From | Marco Moock <mm@dorfdsl.de> |
|---|---|
| Date | 2023-11-22 12:00 +0100 |
| Message-ID | <HCT7z-7cmH-1@gated-at.bofh.it> |
| In reply to | #263771 |
Am 22.11.2023 um 11:29:47 Uhr schrieb Nicolas George: > As you can see, the server is on the …96.0/22 subnet, i.e. …96-…99, > but it sees MAC addresses on the 100 and 103 networks. Are those networks on the same ethernet link? Are some systems with wrong subnet masks on the link and the router has gratious ARP enabled?
[toc] | [prev] | [next] | [standalone]
| From | Marco Moock <mm@dorfdsl.de> |
|---|---|
| Date | 2023-11-22 12:00 +0100 |
| Message-ID | <HCT7z-7cmH-7@gated-at.bofh.it> |
| In reply to | #263772 |
Am 22.11.2023 um 11:51:36 Uhr schrieb Marco Moock: > Are some systems with wrong subnet masks on the link and the router > has gratious ARP enabled? Sorry, not gracious-arp, proxy-arp can be responsible for that.
[toc] | [prev] | [next] | [standalone]
| From | Nicolas George <george@nsup.org> |
|---|---|
| Date | 2023-11-22 12:10 +0100 |
| Message-ID | <HCThf-7cFz-3@gated-at.bofh.it> |
| In reply to | #263773 |
Marco Moock (12023-11-22): > Sorry, not gracious-arp, proxy-arp can be responsible for that. Thanks for clarifying. But AFAIK, with proxy ARP, the network mask covers all the networks covered by the proxy. That is not the case here. Regards, -- Nicolas George
[toc] | [prev] | [next] | [standalone]
| From | Marco Moock <mm@dorfdsl.de> |
|---|---|
| Date | 2023-11-22 12:20 +0100 |
| Message-ID | <HCTqV-7cIH-9@gated-at.bofh.it> |
| In reply to | #263775 |
Am 22.11.2023 um 12:00:52 Uhr schrieb Nicolas George: > Thanks for clarifying. But AFAIK, with proxy ARP, the network mask > covers all the networks covered by the proxy. That is not the case > here. Does your Router have a default route? The it covers 0.0.0.0/0.
[toc] | [prev] | [next] | [standalone]
| From | Nicolas George <george@nsup.org> |
|---|---|
| Date | 2023-11-22 12:00 +0100 |
| Message-ID | <HCT7z-7cmH-11@gated-at.bofh.it> |
| In reply to | #263772 |
Marco Moock (12023-11-22): > Are those networks on the same ethernet link? No, they are on a different VLAN. > Are some systems with wrong subnet masks on the link and the router has > gratious ARP enabled? I do not see what the router has to do with anything. Can you elaborate what you mean? On the server, we never enabled an option to accept ARP information that does not come as a reply to a request from the network stack, if such an option even exists, so even if such a packet came it should not have reached the ARP tables. Regards, -- Nicolas George
[toc] | [prev] | [next] | [standalone]
| From | Marco Moock <mm@dorfdsl.de> |
|---|---|
| Date | 2023-11-22 12:10 +0100 |
| Message-ID | <HCThf-7cFz-9@gated-at.bofh.it> |
| In reply to | #263774 |
Am 22.11.2023 um 11:58:55 Uhr schrieb Nicolas George: > I do not see what the router has to do with anything. Can you > elaborate what you mean? Proxy-ARP offers the possibility to answer ARP requests of addresses outside the own subnet sitting on another ethernet link. In normal cases that is not needed. It is needed when systems exist that don't have the same subnet mask - for whatever reason. It is a niche situation mostly for very old operating systems, so disable it by default on the router. > On the server, we never enabled an option to accept ARP information > that does not come as a reply to a request from the network stack, if > such an option even exists, so even if such a packet came it should > not have reached the ARP tables. I dunno if your system accepts such ARP replies, maybe give it a manual try.
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web