Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #263771 > unrolled thread

Weird MAC address

Started byNicolas George <george@nsup.org>
First post2023-11-22 11:40 +0100
Last post2023-11-22 12:10 +0100
Articles 7 — 2 participants

Back to article view | Back to linux.debian.user


Contents

  Weird MAC address Nicolas George <george@nsup.org> - 2023-11-22 11:40 +0100
    Re: Weird MAC address Marco Moock <mm@dorfdsl.de> - 2023-11-22 12:00 +0100
      Re: Weird MAC address Marco Moock <mm@dorfdsl.de> - 2023-11-22 12:00 +0100
        Re: Weird MAC address Nicolas George <george@nsup.org> - 2023-11-22 12:10 +0100
          Re: Weird MAC address Marco Moock <mm@dorfdsl.de> - 2023-11-22 12:20 +0100
      Re: Weird MAC address Nicolas George <george@nsup.org> - 2023-11-22 12:00 +0100
        Re: Weird MAC address Marco Moock <mm@dorfdsl.de> - 2023-11-22 12:10 +0100

#263771 — Weird MAC address

FromNicolas George <george@nsup.org>
Date2023-11-22 11:40 +0100
SubjectWeird MAC address
Message-ID<HCSOd-7cg4-7@gated-at.bofh.it>
Hi.

Since last we have four MAC addresses in the ARP table of a server that
should not be there:

$ ip route
default via XXX.XXX.98.254 dev eth0 onlink 
XXX.XXX.96.0/22 dev eth0  proto kernel  scope link  src XXX.XXX.98.94 

But:

$ ip neigh | grep -v 'XXX.XXX.9[6789]'
XXX.XXX.103.161 dev eth0 lladdr YY:YY:YY:YY:YY:YY<STALE
XXX.XXX.103.189 dev eth0 lladdr YY:YY:YY:YY:YY:YY STALE
XXX.XXX.100.76 dev eth0 lladdr ZZ:ZZ:ZZ:ZZ:ZZ:ZZ STALE
XXX.XXX.100.86 dev eth0 lladdr ZZ:ZZ:ZZ:ZZ:ZZ:ZZ STALE

$ arp -a | grep -v 'XXX.XXX.9[6789]'
? (XXX.XXX.103.161) at YY:YY:YY:YY:YY:YY [ether] on eth0
? (XXX.XXX.103.189) at YY:YY:YY:YY:YY:YY [ether] on eth0
XXXX.XX.XXX.XX (XXX.XXX.100.76) at ZZ:ZZ:ZZ:ZZ:ZZ:ZZ [ether] on eth0
XXXX.XX.XXX.XX (XXX.XXX.100.86) at ZZ:ZZ:ZZ:ZZ:ZZ:ZZ [ether] on eth0

As you can see, the server is on the …96.0/22 subnet, i.e. …96-…99, but
it sees MAC addresses on the 100 and 103 networks.

I ran tcpdump for some time and saw no ARP packet with these addresses.
And they will not go away by themselves like the rest of the ARP tables.

Does anybody have an inkling about why a Linux kernel would register
neighbors like that?

Regards,

-- 
  Nicolas George

[toc] | [next] | [standalone]


#263772

FromMarco Moock <mm@dorfdsl.de>
Date2023-11-22 12:00 +0100
Message-ID<HCT7z-7cmH-1@gated-at.bofh.it>
In reply to#263771
Am 22.11.2023 um 11:29:47 Uhr schrieb Nicolas George:

> As you can see, the server is on the …96.0/22 subnet, i.e. …96-…99,
> but it sees MAC addresses on the 100 and 103 networks.

Are those networks on the same ethernet link?
Are some systems with wrong subnet masks on the link and the router has
gratious ARP enabled?

[toc] | [prev] | [next] | [standalone]


#263773

FromMarco Moock <mm@dorfdsl.de>
Date2023-11-22 12:00 +0100
Message-ID<HCT7z-7cmH-7@gated-at.bofh.it>
In reply to#263772
Am 22.11.2023 um 11:51:36 Uhr schrieb Marco Moock:

> Are some systems with wrong subnet masks on the link and the router
> has gratious ARP enabled?

Sorry, not gracious-arp, proxy-arp can be responsible for that.

[toc] | [prev] | [next] | [standalone]


#263775

FromNicolas George <george@nsup.org>
Date2023-11-22 12:10 +0100
Message-ID<HCThf-7cFz-3@gated-at.bofh.it>
In reply to#263773
Marco Moock (12023-11-22):
> Sorry, not gracious-arp, proxy-arp can be responsible for that.

Thanks for clarifying. But AFAIK, with proxy ARP, the network mask
covers all the networks covered by the proxy. That is not the case here.

Regards,

-- 
  Nicolas George

[toc] | [prev] | [next] | [standalone]


#263777

FromMarco Moock <mm@dorfdsl.de>
Date2023-11-22 12:20 +0100
Message-ID<HCTqV-7cIH-9@gated-at.bofh.it>
In reply to#263775
Am 22.11.2023 um 12:00:52 Uhr schrieb Nicolas George:

> Thanks for clarifying. But AFAIK, with proxy ARP, the network mask
> covers all the networks covered by the proxy. That is not the case
> here.

Does your Router have a default route?
The it covers 0.0.0.0/0.

[toc] | [prev] | [next] | [standalone]


#263774

FromNicolas George <george@nsup.org>
Date2023-11-22 12:00 +0100
Message-ID<HCT7z-7cmH-11@gated-at.bofh.it>
In reply to#263772
Marco Moock (12023-11-22):
> Are those networks on the same ethernet link?

No, they are on a different VLAN.

> Are some systems with wrong subnet masks on the link and the router has
> gratious ARP enabled?

I do not see what the router has to do with anything. Can you elaborate
what you mean?

On the server, we never enabled an option to accept ARP information that
does not come as a reply to a request from the network stack, if such an
option even exists, so even if such a packet came it should not have
reached the ARP tables.

Regards,

-- 
  Nicolas George

[toc] | [prev] | [next] | [standalone]


#263776

FromMarco Moock <mm@dorfdsl.de>
Date2023-11-22 12:10 +0100
Message-ID<HCThf-7cFz-9@gated-at.bofh.it>
In reply to#263774
Am 22.11.2023 um 11:58:55 Uhr schrieb Nicolas George:

> I do not see what the router has to do with anything. Can you
> elaborate what you mean?

Proxy-ARP offers the possibility to answer ARP requests of addresses
outside the own subnet sitting on another ethernet link.
In normal cases that is not needed. It is needed when systems exist
that don't have the same subnet mask - for whatever reason.

It is a niche situation mostly for very old operating systems, so
disable it by default on the router.

> On the server, we never enabled an option to accept ARP information
> that does not come as a reply to a request from the network stack, if
> such an option even exists, so even if such a packet came it should
> not have reached the ARP tables.

I dunno if your system accepts such ARP replies, maybe give it a manual
try.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web