Ad Widget

Collapse

Iptable logs

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • jyoung
    Junior Member
    • Mar 2005
    • 13

    #1

    Iptable logs

    I have been getting iptable log messages on the Zabbix port, 10050.
    I'm using 1.1alpha7 at the moment, but I was getting the message with 1.0 as well.

    90% of the time these logs are truncated and do not show the full error log.

    IE:
    Mar 23 13:35:01 server kernel: =10050 DPT=53326 WINDOW=5792 RES=0x00 ACK URGP=0 OPT (0101080A29307A1529306B41)
    Mar 23 14:10:00 server kernel: P SPT=10050 DPT=54754 WINDOW=5792 RES=0x00 ACK PSH URGP=0 OPT (0101080A2933AE1329339F3F)
    Mar 23 14:35:00 server kernel: 5963 DF PROTO=TCP SPT=10050 DPT=55796 WINDOW=5792 RES=0x00 ACK FIN URGP=0 OPT (0101080A2935F80D2935E939)
    Mar 23 14:50:00 server kernel: 52 TOS=0x00 PREC=0x00 TTL=64 ID=39463 DF PROTO=TCP SPT=56419 DPT=10050 WINDOW=32767 RES=0x00 ACK URGP=0 OPT (0101080A293748DC293748DC)
    I do not believe this is a Zabbix issue, beyond perhaps a misconfiguration on my part. Perhaps the number of suckers vs. agents? Has anyone else experienced such an issue? As you can see above, the messages to the log file are not at a fixed time; sometimes it happens, sometimes it does not. I have limited Zabbix to two boxes, one running agentd the other agentd+serverd.

    There are RH9 boxes, although I've experienced the same thing when testing the software out on Fedora Core 3 servers.

    There is nothing blocking the ports in my iptable rules and I have not found anything related to this with a forum or google search. I feel I'm missing some details in here and will add to the post when I remember them.

    Any help or ideas to fix this are appreciated. I hope to soon post some tips/hints that I've used to expand Zabbix in the last few weeks while learning to use it to it's full potential.

    Thanks,

    Jesse
  • welshpjw
    Member
    • Mar 2005
    • 50

    #2
    1. is the iptables log from the client or server?
    2. is zabbix server/client genterating correct information?
    3. is the iptables log from a box acting as an IDS (intrusion detection system) also?
    4. does your iptables rules "block all that is not allowed" or "allow all but what I block"?

    Comment

    • jyoung
      Junior Member
      • Mar 2005
      • 13

      #3
      Originally posted by welshpjw
      1. is the iptables log from the client or server?
      Server, the client acts just fine. Once started I also receive mysql port logs from another box, but this is just some freak networking problem and Zabbix has just helped point it out.

      Originally posted by welshpjw
      2. is zabbix server/client genterating correct information?
      Yes, all information recorded is correct.

      Originally posted by welshpjw
      3. is the iptables log from a box acting as an IDS (intrusion detection system) also?
      4. does your iptables rules "block all that is not allowed" or "allow all but what I block"?
      It appears that the other system administrator has it setup as a lowkey IDS. Instead of blocking all that is not specified as allowed he has it being logged. This would be what is making the log entries. I had added destitnation port 10050, now adding source port 10050 to see if that will cut back on the logs.

      Thanks for the help/suggestions/clues. Its all iptables junk, I just need to think clearer how Zabbix is accessing the network and open those ports accordingly.

      Comment

      • jyoung
        Junior Member
        • Mar 2005
        • 13

        #4
        Working since last post. Adding
        iptables -I INPUT -s 127.0.0.1 -p tcp -m tcp --sport 10050 -j ACCEPT
        stoped the iptables logging messages. I haven't had a false log one for 6+ hrs so I'm calling it fixed. Once again, thanks for the help.

        Jesse
        Last edited by jyoung; 25-03-2005, 02:29. Reason: Added items

        Comment

        Working...