Re: Large number of invalid packets detected

Futhermore here is some output from tcpdump which shows a very high rate
of checksum errors in the packets:

tcpdump -s1500 -vvv port 80|grep -i incorrect
(I only ran this for a few seconds and here is what it output - at the
time I was getting requests at the rate of 1 request every 2 seconds)

16:37:22.719802 IP (tos 0x0, ttl 64, id 23246, offset 0, flags [DF],
proto TCP (6), length 693) domU-xxx > xxx.xxx.net.netclip: P, cksum
0x5fc4 (incorrect (-> 0xb52e), 26461:27114(653) ack 447 win 6432
16:37:29.492240 IP (tos 0x0, ttl 64, id 33170, offset 0, flags [DF],
proto TCP (6), length 1290) domU-xxx > xxxx.xxxx.com.57132: P, cksum
0x8131 (incorrect (-> 0x24da), 7241:8479(1238) ack 583 win 55
<nop,nop,timestamp 478987053 46606982>
16:37:30.047027 IP (tos 0x0, ttl 64, id 2132, offset 0, flags [DF],
proto TCP (6), length 89) domU-xxx > xxx.xxx.net.52956: P, cksum
0x0da0 (incorrect (-> 0x3f1d), 7241:7278(37) ack 396 win 54
<nop,nop,timestamp 478987191 384369485>
16:37:31.966523 IP (tos 0x0, ttl 64, id 14827, offset 0, flags [DF],
proto TCP (6), length 1294) domU-xxx > xxxx.xxxx.dialog-port: P,
cksum 0x1153 (incorrect (-> 0xc555), 26281:27535(1254) ack 415 win
6432
16:37:32.155399 IP (tos 0x0, ttl 64, id 39841, offset 0, flags [DF],
proto TCP (6), length 871) domU-xxx > x.y.z.a.51963: P, cksum 0xd32a
(incorrect (-> 0x9716), 26281:27112(831) ack 412 win 6432
16:37:32.636392 IP (tos 0x0, ttl 64, id 58696, offset 0, flags [DF],
proto TCP (6), length 1450) domU-xxx >
mobilexxxx.xx.x.x.llsurfup-http: ., cksum 0xe939 (incorrect (->
0x3c94), 23971:25381(1410) ack 293 win 6432
16:37:33.258956 IP (tos 0x0, ttl 64, id 58697, offset 0, flags [DF],
proto TCP (6), length 1450) domU-xxx >
mobilexxx.x.x.x.llsurfup-http: ., cksum 0xe939 (incorrect (->
0x743f), 25381:26791(1410) ack 293 win 6432
16:37:33.258963 IP (tos 0x0, ttl 64, id 58698, offset 0, flags [DF],
proto TCP (6), length 364) domU-xxx > mobilexxx.x.x.x.llsurfup-http:
P, cksum 0xe4fb (incorrect (-> 0x89ee), 26791:27115(324) ack 293 win
6432
16:37:38.080571 IP (tos 0x0, ttl 64, id 64581, offset 0, flags [DF],
proto TCP (6), length 1290) domU-xxx > x.x.x.x.x.6096: P, cksum
0x6517 (incorrect (-> 0x5f33), 7301:8551(1250) ack 465 win 6432

On Sun, 18 May 2008 13:49:32 -0700 (PDT)
Rt Ibmer [email protected] wrote:

Futhermore here is some output from tcpdump which shows a very high rate
of checksum errors in the packets:

If your NIC does checksumming in hardware, then tcpdump will likely
report
invalid cksums in packet headers.

Jure Pečar
http://jure.pecar.org/

This forum is not affiliated to the Ruby language, Ruby on Rails framework, nor any Ruby applications discussed here.

| Privacy Policy | Terms of Service | Remote Ruby Jobs