Dual NIC, problem s nedostupnosti

Lubos Dolezal jf at rtfm.cz
Fri Mar 27 14:51:09 CET 2009


Dobry den,

Narazil jsem na mozna "zajimavy" problem u sitovani na 7.1-RELEASE (amd64).

Server ma dve sitova rozhrani pripojena v rozdilnych sitich (bge0, bge1):

---
bge0 at pci0:2:0:0: class=0x020000 card=0x81491043 chip=0x165914e4 rev=0x01 hdr=0x00
bge1 at pci0:4:4:0: class=0x020000 card=0x81481043 chip=0x165314e4 rev=0x03 hdr=0x00
---

Nakonfigurovane jsou nasledovne:

---
ifconfig_bge0="inet 172.25.11.23 netmask 255.255.255.0"
ifconfig_bge1="inet 172.25.9.12 netmask 255.255.255.0"

defaultrouter="172.25.11.1"


bge0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
         options=9b<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,VLAN_HWCSUM>
         ether 00:11:d8:13:bf:02
         inet 172.25.11.23 netmask 0xffffff00 broadcast 172.25.11.255
         media: Ethernet autoselect (1000baseTX <full-duplex>)
         status: active
bge1: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
         options=9b<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,VLAN_HWCSUM>
         ether 00:11:d8:13:bf:03
         inet 172.25.9.12 netmask 0xffffff00 broadcast 172.25.9.255
         media: Ethernet autoselect (1000baseTX <full-duplex>)
         status: active
---

Ted k tomu "problemu". Pokud je rozhrani "bge1" aktivni (a nakonfigurovane na 
uvedenou adresu) nelze se z jineho serveru v siti "172.25.9.0/24" dostat na 
sitove sluzby bezici na adrese 172.25.11.23 (rozhrani bge0). Napr. z 172.25.9.10:

---
$ telnet 172.25.11.23 22
Trying 172.25.11.23...
telnet: Unable to connect to remote host: Connection timed out
---

SSHd na IP 172.25.11.23 bezi a je z jinych siti pristupne.

Pokud se bge1 neaktivuje, komunikace je ze vsech siti (tedy i z 172.25.9.0/24) 
bez problemu.

Z vypisu routovaci tabulky (z 172.25.9.14 jsem take zkousel "telnet" na 22/TCP)

---
# netstat -rn
Routing tables

Internet:
Destination        Gateway            Flags    Refs      Use  Netif Expire
default            172.25.11.1        UGS         0      346   bge0
127.0.0.1          127.0.0.1          UH          0        0    lo0
172.25.9.0/24      link#2             UC          0        0   bge1
172.25.9.10        00:16:3e:1e:44:3e  UHLW        1       46   bge1     50
172.25.9.14        00:16:3e:30:9e:f0  UHLW        1        8   bge1   1174
172.25.9.25        00:16:3e:3d:cf:1b  UHLW        1       67   bge1    925
172.25.11.0/24     link#1             UC          0        0   bge0
172.25.11.1        00:17:5a:88:67:cb  UHLW        2        0   bge0     53
172.25.11.10       00:16:3e:22:d8:f0  UHLW        1        8   bge0   1120

Internet6:
Destination                       Gateway                       Flags      Netif 
Expire
::1                               ::1                           UHL         lo0
fe80::%lo0/64                     fe80::1%lo0                   U           lo0
fe80::1%lo0                       link#3                        UHL         lo0
ff01:3::/32                       fe80::1%lo0                   UC          lo0
ff02::%lo0/32                     fe80::1%lo0                   UC          lo0
---

mi to prijde, jako by spojeni urcena pro sit "172.25.9.0/24" byla smerovana na 
bge1. A to bez ohledu, ze "prisla" a byla urcena pro bge0.

Je neco v konfiguraci, co toto zpusobuje, pripadne je treba jeste neco 
dokonfigurovat (v ramci sitovych sluzeb), aby byla 172.25.11.23 dostupna ze 
vsech siti i presto, ze bude aktivni druhe rozhrani?

Diky.

Lubos Dolezal



More information about the Users-l mailing list