Weird ip6tables mac= logging

Weird ip6tables mac= logging

Post by Rob van der Putte » Fri, 25 Mar 2011 03:09:29



Hi there

A bit from the syslog (UTC + 1);
Mar 23 06:04:27 sput kernel: [245625.292575] IN=xs6all OUT=
MAC=20:00:40:2f:ae:8f:0a:00:00:96:ff:03:00:21:45:00:00:5c:00:00:40:00:3e:29:c3:ba:c2:6d:05:f1:50:65:5f:fb:60:00:00:00:00:20:06:74:20:02:18:e6:b8:dc:00:00:00:00:00:00:18:e6:b8:dc:20:01:08:88:15:33:00:01:00:00:00:00:00:00:00:01:cb:ec:1f:90:fd:63:87:3b:00:00:00:00:80:c2:20:00:dd:de:00:00:02:04:04:c4:01:03:03:08:01:01:04:02:ef:67:31:20:30:35:3a:30:33:3a:32:35:20:47:4d:54:0d:0a:53:65:72:76:65:72:3a:20:41:70:61:63:68:65:2f:32:2e:32:2e:31:36:20:28:44
TUNNEL=194.109.5.241->80.101.95.251
SRC=2002:18e6:b8dc:0000:0000:0000:18e6:b8dc
DST=2001:0888:1533:0001:0000:0000:0000:0001 LEN=72 TC=0 HOPLIMIT=116
FLOWLBL=0 PROTO=TCP SPT=52204 DPT=8080 WINDOW=8192 RES=0x00 CWR ECE SYN
URGP=0
Mar 23 06:04:30 sput kernel: [245628.308577] IN=xs6all OUT=
MAC=00:00:eb:01:00:00:7e:ff:7d:23:ff:03:00:21:45:00:00:5c:00:00:40:00:3e:29:c3:ba:c2:6d:05:f1:50:65:5f:fb:60:00:00:00:00:20:06:74:20:02:18:e6:b8:dc:00:00:00:00:00:00:18:e6:b8:dc:20:01:08:88:15:33:00:01:00:00:00:00:00:00:00:01:cb:ec:1f:90:fd:63:87:3b:00:00:00:00:80:c2:20:00:dd:de:00:00:02:04:04:c4:01:03:03:08:01:01:04:02:ef:67:62:2f:6b:69:74:65:2f:20:48:54:54:50:2f:31:2e:31:0d:0a:41:63:63:65:70:74:3a:20:74:65:78:74:2f:68:74:6d:6c:2c:74:65:78:74
TUNNEL=194.109.5.241->80.101.95.251
SRC=2002:18e6:b8dc:0000:0000:0000:18e6:b8dc
DST=2001:0888:1533:0001:0000:0000:0000:0001 LEN=72 TC=0 HOPLIMIT=116
FLOWLBL=0 PROTO=TCP SPT=52204 DPT=8080 WINDOW=8192 RES=0x00 CWR ECE SYN
URGP=0
Mar 23 06:04:36 sput kernel: [245634.328566] IN=xs6all OUT=
MAC=00:00:8f:01:00:00:7e:ff:7d:23:ff:03:00:21:45:00:00:58:00:00:40:00:3e:29:c3:be:c2:6d:05:f1:50:65:5f:fb:60:00:00:00:00:1c:06:74:20:02:18:e6:b8:dc:00:00:00:00:00:00:18:e6:b8:dc:20:01:08:88:15:33:00:01:00:00:00:00:00:00:00:01:cb:ec:1f:90:fd:63:87:3b:00:00:00:00:70:02:20:00:f2:ad:00:00:02:04:04:c4:01:01:04:02:91:bf:5e:64:08:88:15:33:00:01:00:00:00:00:00:00:00:01:00:7b:00:7b:00:38:c6:4f:23:01:06:ed:00:00:00:00:00:00:00:41:50:50:53:00:d1:33:fd:1e
TUNNEL=194.109.5.241->80.101.95.251
SRC=2002:18e6:b8dc:0000:0000:0000:18e6:b8dc
DST=2001:0888:1533:0001:0000:0000:0000:0001 LEN=68 TC=0 HOPLIMIT=116
FLOWLBL=0 PROTO=TCP SPT=52204 DPT=8080 WINDOW=8192 RES=0x00 SYN URGP=0

Those 'MAC=' strings are rather weird. There are even bits of ascii in
there (converting :XX to an ascii value);

  05:03:25 GMT
Server: Apache/2.2.16

/kite/ HTTP/1.1
Accept: text/html,text

'xs6all' is a v4tunnel interface. Which doesn't have a mac address.

Any idea what is going on?

Regards,
Rob

 
 
 

1. Weird Ping, weird FTP, weird Telnet... HELP!!!

Can anyone diagnose this for me?

I'm in the process of building up a firewall but at some stage I musta
messed up and am now getting really weird results.

This is the results of a ping from 192.168.0.1 to 192.168.0.1 (the box
which will become the fireawall).

# PING 192.168.0.1
PING 192.168.0.1 (192.168.0.1) from 192.168.0.1 : 56(84) bytes of
data.
64 bytes from 192.168.0.1: icmp_seq=0 ttl=225 time=0.7ms
64 bytes from 192.168.0.1: icmp_seq=1 ttl=225 time=80001.0ms
64 bytes from 192.168.0.1: icmp_seq=2 ttl=225 time=160000.9ms
64 bytes from 192.168.0.1: icmp_seq=3 ttl=225 time=240000.8ms
64 bytes from 192.168.0.1: icmp_seq=4 ttl=225 time=320000.8ms
64 bytes from 192.168.0.1: icmp_seq=5 ttl=225 time=400000.7ms
64 bytes from 192.168.0.1: icmp_seq=6 ttl=225 time=480000.7ms

^c

--- 192.168.0.1 ping statistics ---
509 packets transmitted, 8 packets received, 98% packet loss
round-trip min/avg/max = 0.7/280000.7/560000.6 ms

This also happens when I do it from other machines behind the firewall
but I was very surprised when it did it when pinging itself.

Theres a pattern of 80000ms increments between successful pings...
Can't figure out whats wrong though.

If I try to telnet or FTP, I have to wait for an eternity b4 the login
prompt appears after the initial "connected" msg. But once I login
there is no problem using the console or transferring files. Same
thing for other machines to 192.168.0.1. So the network is "working"
but its waiting for something.

Has anyone had this happen to them b4 and manage to solve it?

Any help appreciated

Regards,

2. Link failover with ping

3. Weird, weird, weird issue ....

4. Mounting a Mitsumi FX100D 2x CD-ROM

5. comp.sys.mac.misc comp.sys.mac.system comp.sys.mac.apps

6. Masq and X question

7. Problems with networking on linux box, weird MAC broadcast messages

8. bcheck/dbx question

9. Weird MAC address results with 2 network cards?

10. weird MAC address change on the fly?

11. weird interaction between netscape 4 mac, cern server, "post"

12. Weird nic/mac change problem

13. ip6tables MASQUERADE?