Jump to content

Strange network issue


mudmanc4

Recommended Posts

Layout brief-

server1 has IP aaa.aaa.aaa.aaa on eth0 - drop1

 

server3 has IP bbb.bbb.bbb.bbb on eth0 drop2

 

server1 eth1 cross connects with server3 on eth1 natted via 1:1 (public IP's>>private IP subnet) set from server1 for CT's on vmbr1 of server3

 

All appears to function properly. 

 

Question:

How is IP bbb.bbb.bbb.bbb pointed to eth0 on server1, making hundreds of connection attempts through LAN/ cross connect to IP aaa.aaa.aaa.aaa on eth0 of server1 via private IP subnet. 

(they are constellix requests) that I set. They report to server2 harvested off email server (server2) as well as nagios. Which is currently not happening. 

 

There is obviously more than one thing going on in the config for eth0/drop2/server3

Though I have flushed all iptables rules on server3 and removed vmbr0 - however firewall logs within (server1) show constant attempts from IP bbb.bbb.bbb.bbb to aaa.aaa.aaa.aaa and firewall is obviously blocking them. 

 

I should be able to trace this, however considering I cannot ping/tracerout , nmap use wireshark to eth0/server3 (other than the gateway and or broadcast) because there is some redirect if I may that is pointing IP bbb.bbb.bbb.bbb through the internal network. 

 

Server3 is debian based, so where would the next place to look be for this hidden IPV4 forward ?/ redirect? mapping? I've checked /etc/host /etc/hosts  /etc/sysctl.conf /etc/resolv.conf (there is no /etc/resolve/resolv.conf) and iptables -L shows a fresh wide open route. There are no ifup/ preup statements. 

 

Hope I explained this issue well enough. I must be overlooking something simple. 

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below.
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...