Re: syslog spam: TCP segment has incorrect auth options set

From: Christian Kujau
Date: Sun Jan 07 2024 - 14:27:40 EST


On Thu, 4 Jan 2024, Christian Kujau wrote:
> On Thu, 4 Jan 2024, Dmitry Safonov wrote:
> > Yeah, I guess it's possible to down the severity of these logs, but may
> > be unexpected by admins: TCP-MD5 messages existed for long time and
> > there may be userspace that expects them (i.e. in arista there are tests
> > that look for these specific messages - those would be easy to fix, but
> > there may be others outside this company).
>
> Understood, thanks for explaining that.
>
> > While thinking on the origin of your issue, it seems that the logs
> > produced by either TCP-MD5 or TCP-AO are desired by a user when they
> > add/use the authentication. Could you try this and see if that solves
> > the issue for you?
>
> Thanks for preparing that patch so quickly, did not expect that :-)
>
> I've applied this on top of 6.7.0-rc8 and will report back if I see those
> messages again in the next days.

No messages so far, great!

Tested-by: Christian Kujau <lists@xxxxxxxxxxxxxxx>

Thanks again for fixing this so quickly,
Christian.
--
BOFH excuse #323:

Your processor has processed too many instructions. Turn it off immediately, do not type any commands!!