Been having problems with zabbix passive traffic flooding my UFW log with the last rst packet coming from the zabbix agent. I think that after the server sends its rst, it closes the socket and the agent on the client sends one to two more rst packets that are flagged by UFW as not part of the original tcp connection and are blocked.
I have no problems with the data coming back at all, but the fact that the clients are sending these rst packets after the server closes the connection is annoying, and makes it harder to review my UFW log for actual blocked connections.
So why does the zabbix agent have this behavior?
UFW Log:
Nov 11 11:20:38 nms kernel: [54047.242636] [UFW BLOCK] IN=enp2s0 SRC=172.20.20.4 DST=10.10.3.2 LEN=40 TOS=0x00 PREC=0x00 TTL=62 ID=0 DF PROTO=TCP SPT=10050 DPT=57084 WINDOW=0 RES=0x00 RST URGP=0
I have no problems with the data coming back at all, but the fact that the clients are sending these rst packets after the server closes the connection is annoying, and makes it harder to review my UFW log for actual blocked connections.
So why does the zabbix agent have this behavior?
UFW Log:
Nov 11 11:20:38 nms kernel: [54047.242636] [UFW BLOCK] IN=enp2s0 SRC=172.20.20.4 DST=10.10.3.2 LEN=40 TOS=0x00 PREC=0x00 TTL=62 ID=0 DF PROTO=TCP SPT=10050 DPT=57084 WINDOW=0 RES=0x00 RST URGP=0
Comment