LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 01-30-2009, 12:09 AM   #1
soumen1974
LQ Newbie
 
Registered: Jan 2009
Posts: 2

Rep: Reputation: 0
/var/log/messages shows IN=eth0 OUT


Hi

I have checked my log files in my Linux system and it has a message (/var/log/message)

Jan 30 06:46:27 dns-nord2 kernel: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:b0:d0:3e:c9:21:08:00 SRC=10.178.24.32 DST=10.178.25.255 LEN=229 TOS=0x00 PREC=0x00 TTL=128 ID=23056 PROTO=UDP SPT=138 DPT=138 LEN=209


The name of my Linux system is dns-nord2 and it is a DNS server (Bind 9). Now the problem is, the router to which this server is connected shows a lot of traffic passes thru this server. I checked the log file and found the entries (given above) with SRC address of different systems in LAN(in the above example it is 10.178.24.32)

The IP address of the DNS server is 10.178.24.30. Please help as I could not make out what it is though I suspect it is some kind of broadcast (from the DST address 10.178.25.255).
 
Old 01-30-2009, 02:42 AM   #2
bathory
LQ Guru
 
Registered: Jun 2004
Location: Piraeus
Distribution: Slackware
Posts: 13,163
Blog Entries: 1

Rep: Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032
Quote:
I checked the log file and found the entries (given above) with SRC address of different systems in LAN(in the above example it is 10.178.24.32)
This is windows boxes sending out netbios packets. Notice the protocol and the source/destination ports.
 
Old 01-30-2009, 05:28 AM   #3
soumen1974
LQ Newbie
 
Registered: Jan 2009
Posts: 2

Original Poster
Rep: Reputation: 0
Thanks a lot for your prompt reply.....
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
/var/log/messages and /var/log/cron not working sigkill Linux - Software 6 08-09-2008 01:08 PM
/var/log/messages is empty, and also dmesg shows nothing beagle2 Linux - General 5 11-08-2005 08:12 AM
Redirecting the kernel messages to file other than /var/log/messages jyotika_b83 Linux - General 3 04-28-2005 06:39 PM
/var/log/messages shows failed login attempts... plan9 Linux - Security 8 08-08-2004 12:52 PM
eth0 will not restart. Errors in /var/log/messages soren625 Linux - Networking 8 06-05-2004 12:43 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 04:27 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration