Re: duplicate ICMP response packets?

Bart De Schuymer <[email protected]>
Newsgroups gmane.linux.network.bridge.ebtables.user
Message-ID <[email protected]>
Op vr, 10-06-2005 te 07:16 -0400, schreef Jay Libove:
> Thanks again to those who helped me get my curious external proxy ARP
> configuration working last month.
> 
> I have noticed something since then:  I have a couple of PING processes
> set up to monitor reliability of my Internet connection (one PINGs the
> access device at the immediate other end of my DSL line, and the other
> PINGs the next hop outside of the local POP, to help isolate problems to
> either the line itself or something more in the ISP's core).  Since I put
> my bridge configuration in place to allow an unaddressed ethernet
> interface to receive and respond to ARPs, my two PINGs are getting
> duplicate answers for every packet sent.  Here's one of the regular emails
> I get from the processes:
> 
> > From [email protected] Fri May 27 15:59:57 2005
> > Date: Fri, 27 May 2005 15:59:56 -0400
> > From: Cron Daemon <[email protected]>
> > To: [email protected]
> > Subject: Cron <root@panther7> /usr/local/bin/ISP-ping.sh 4
> >
> > Fri May 27 15:59:56 EDT 2005 gate [216.27.163.1]:   --- 216.27.163.1 ping statistics ---
> > 2868 packets transmitted, 2868 received, +2865 duplicates, 0% packet loss, time 14334611ms
> > rtt min/avg/max/mdev = 12.792/17.115/414.140/13.008 ms, pipe 2
> > Fri May 27 15:59:56 EDT 2005 uplink [69.17.82.170]: --- 69.17.82.170 ping statistics ---
> > 2868 packets transmitted, 2868 received, +2866 duplicates, 0% packet loss, time 14334598ms
> > rtt min/avg/max/mdev = 25.212/29.949/426.481/9.366 ms, pipe 2
> 
> 
> Here's a live example:
> [root@panther7 hde4]# ping -c 2 216.27.163.1
> PING 216.27.163.1 (216.27.163.1) 56(84) bytes of data.
> 64 bytes from 216.27.163.1: icmp_seq=0 ttl=127 time=16.7 ms
> 64 bytes from 216.27.163.1: icmp_seq=0 ttl=126 time=17.0 ms (DUP!)
> 64 bytes from 216.27.163.1: icmp_seq=1 ttl=127 time=13.9 ms

The ttl is lower on the duplicate. Looks like one packet is sent through
a bridge and the duplicate through a router.
The bridge certainly is not responsible for changing the ttl. Something
is probably wrong in your network setup. Check the MAC source address of
both packets...

cheers,
Bart




-------------------------------------------------------
This SF.Net email is sponsored by: NEC IT Guy Games.  How far can you shotput
a projector? How fast can you ride your desk chair down the office luge track?
If you want to score the big prize, get to know the little guy.  
Play to win an NEC 61" plasma display: http://www.necitguy.com/?r=20
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.