Re: ip_rt_advice

Andi Kleen (ak@muc.de)
Thu, 8 Apr 1999 18:55:02 +0200


On Thu, Apr 08, 1999 at 05:12:41PM +0200, Richard B. Johnson wrote:
> On Thu, 8 Apr 1999, Denis Chapligin wrote:
>
> > Здравствуйте
> >
> > On 8 Apr 1999, Andi Kleen wrote:
> >
> > > > I have a strange messages at /var/log/debug:
> > > > Apr 7 19:25:00 hurricane kernel: ip_rt_advice: redirect to 194.186.140.201/00 dropped
> > > > Apr 7 19:25:14 hurricane kernel: ip_rt_advice: redirect to 194.186.140.201/00 dropped
> > > >
> > > > But this addresses are really exist in my network. During this messages,
> > > > machines with this ip are not available. What does this mean?
> > >
> > > Someone sent you a ICMP redirect for these IPs. The kernel installed
> > > a temporary route for it. Because these hosts didn't answer it concludes
> > > after some time that the redirect was bad and removes the temporary route.
> > > If it bothers you feel free to comment it out, but it would be better to
> > > fix the routing so that no ICMP redirect is needed.
> > >
> > I don't need routing for this machines, because they all are in one
> > ehternet segment. So, i can't understand, where the problem with
> > routing? May be this is an hacker attack?
> > Denis Chapligin
> >
>
> Check to see if any of the machines are running the routed daemon. This
> is running by default on Sun machines. This causes them to advertise
> routes (even though they share the same wire as everybody else). This
> results in strange routing-table entries on cooperating machines and
> duplicate packets on the physical link.

ICMP route redirect has nothing to do with the route daemon, it is generated
on Unix systems by the Kernel (on Linux only when it is not configured
as a router, as per RFC1812)

Usually it happens when you have missing routes to some box on the same network
and your default gateway is misconfigured and issues redirects.

In general you're right though, dynamic routing (routed) on non-router boxes
does usually more harm than good, with the exception of router discovery.

-Andi

-- 
This is like TV. I don't like TV.

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu Please read the FAQ at http://www.tux.org/lkml/