TCLUG Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Packet logging (again)



Okay, I think I've found a small problem relating to packet logging on
the 2.2.14 kernel, and maybe someone can try and verify this..

I've been having trouble for a while where my system will suddenly stop
logging any set of packets that are supposed to be logged using the
rules in my IPChains setup.  The problem appears to show up when I have
changed the IP address of my system (or have attempted to).  I first
realized something strange was going on when I would insert the IPv6
module, which attempts to auto-configure the interface.  As soon as I
inserted that module, logging stopped, and the only way I could find to
get it back was to restart the system.  Again this morning, I see that
the logging on my system has stopped, even though I have _not_ used the
IPv6 module during this boot.  However, I _did_ bring down my eth0
interface, bring it back up with pump (RedHat's DHCP client), then bring
that down, and bring the interface back up with a static configuration I
have.

Well, anyway, I don't really understand what's going on, just that the
logging disappears after a while.  However, my best guess is that the
kernel `forgets' that it was supposed to be logging packets after an
interface changes its IP address..  If anyone else can confirm this
behavior, I'd like to hear about it (and perhaps a way to fix it, too..)

I suppose I should just look at some of the patched kernels, though..
:-p

-- 
 _  _  _  _ _  ___    _ _  _  ___ _ _  __   Life would be easier if I 
/ \/ \(_)| ' // ._\  / - \(_)/ ./| ' /(__   had the source code. 
\_||_/|_||_|_\\___/  \_-_/|_|\__\|_|_\ __)                             
 [ Mike Hicks | http://umn.edu/~hick0088/ | mailto:hick0088@umn.edu ]