Заметил, что на своем vds иногда необъяснимо растет входящий траффик на сервер, хотя в активных сетевых подключениях никаких "левых" соедиенний нет.
Решил посомтреть что там твориться через tcpdump.
Он выводит:
zorro@pr5:~$ sudo tcpdump -i eth0
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth0, link-type EN10MB (Ethernet), capture size 96 bytes
20:22:26.1285838271 Broadcast Unknown SSAP 0x56 > 00:00:00:00:00:00 (oui Ethernet) Unknown DSAP 0x20 Supervisory, Receiver not Ready, rcv seq 36, Flags [Response], length 4294967282
20:22:26.1285838271 Broadcast Unknown SSAP 0x56 > 00:00:00:00:00:00 (oui Ethernet) Unknown DSAP 0x20 Supervisory, Receiver not Ready, rcv seq 36, Flags [Response], length 4294967282
20:22:26.1285838271 Broadcast Unknown SSAP 0x56 > 00:00:00:00:00:00 (oui Ethernet) Unknown DSAP 0x20 Supervisory, Receiver not Ready, rcv seq 36, Flags [Response], length 4294967282
20:22:26.1285838271 Broadcast Unknown SSAP 0x56 > 00:00:00:00:00:00 (oui Ethernet) Unknown DSAP 0x20 Supervisory, Receiver not Ready, rcv seq 36, Flags [Response], length 4294967282
20:22:26.1285838271 Broadcast Unknown SSAP 0x56 > 00:00:00:00:00:00 (oui Ethernet) Unknown DSAP 0x20 Supervisory, Receiver not Ready, rcv seq 36, Flags [Response], length 4294967282
20:22:26.1285838271 Broadcast Unknown SSAP 0x56 > 00:00:00:00:00:00 (oui Ethernet) Unknown DSAP 0x20 Supervisory, Receiver not Ready, rcv seq 36, Flags [Response], length 4294967282
20:22:26.1285838271 Broadcast Unknown SSAP 0x56 > 00:00:00:00:00:00 (oui Ethernet) Unknown DSAP 0x20 Supervisory, Receiver not Ready, rcv seq 36, Flags [Response], length 4294967282
20:22:26.1285838271 Broadcast Unknown SSAP 0x56 > 00:00:00:00:00:00 (oui Ethernet) Unknown DSAP 0x20 Supervisory, Receiver not Ready, rcv seq 36, Flags [Response], length 4294967282
20:22:26.1285838271 Broadcast Unknown SSAP 0x56 > 00:00:00:00:00:00 (oui Ethernet) Unknown DSAP 0x20 Supervisory, Receiver not Ready, rcv seq 36, Flags [Response], length 4294967282
20:22:26.1285838271 Broadcast Unknown SSAP 0x56 > 00:00:00:00:00:00 (oui Ethernet) Unknown DSAP 0x20 Supervisory, Receiver not Ready, rcv seq 36, Flags [Response], length 4294967282
20:22:26.1285838271 Broadcast Unknown SSAP 0x56 > 00:00:00:00:00:00 (oui Ethernet) Unknown DSAP 0x20 Supervisory, Receiver not Ready, rcv seq 36, Flags [Response], length 4294967282
20:22:26.1285838271 Broadcast Unknown SSAP 0x56 > 00:00:00:00:00:00 (oui Ethernet) Unknown DSAP 0x20 Supervisory, Receiver not Ready, rcv seq 36, Flags [Response], length 4294967282
20:22:26.1285838271 Broadcast Unknown SSAP 0x56 > 00:00:00:00:00:00 (oui Ethernet) Unknown DSAP 0x20 Supervisory, Receiver not Ready, rcv seq 36, Flags [Response], length 4294967282
20:22:26.1285838271 Broadcast Unknown SSAP 0x56 > 00:00:00:00:00:00 (oui Ethernet) Unknown DSAP 0x20 Supervisory, Receiver not Ready, rcv seq 36, Flags [Response], length 4294967282
20:22:26.1285838271 Broadcast Unknown SSAP 0x56 > 00:00:00:00:00:00 (oui Ethernet) Unknown DSAP 0x20 Supervisory, Receiver not Ready, rcv seq 36, Flags [Response], length 4294967282
20:22:26.1285838271 Broadcast Unknown SSAP 0x56 > 00:00:00:00:00:00 (oui Ethernet) Unknown DSAP 0x20 Supervisory, Receiver not Ready, rcv seq 36, Flags [Response], length 4294967282
20:22:26.1285838271 Broadcast Unknown SSAP 0x56 > 00:00:00:00:00:00 (oui Ethernet) Unknown DSAP 0x20 Supervisory, Receiver not Ready, rcv seq 36, Flags [Response], length 4294967282
20:22:26.1285838271 Broadcast Unknown SSAP 0x56 > 00:00:00:00:00:00 (oui Ethernet) Unknown DSAP 0x20 Supervisory, Receiver not Ready, rcv seq 36, Flags [Response], length 4294967282
20:22:26.1285838271 Broadcast Unknown SSAP 0x56 > 00:00:00:00:00:00 (oui Ethernet) Unknown DSAP 0x20 Supervisory, Receiver not Ready, rcv seq 36, Flags [Response], length 4294967282
20:22:26.1285838271 Broadcast Unknown SSAP 0x56 > 00:00:00:00:00:00 (oui Ethernet) Unknown DSAP 0x20 Supervisory, Receiver not Ready, rcv seq 36, Flags [Response], length 4294967282
tcpdump: pcap_loop: corrupted frame on kernel ring mac offset 94 + caplen 170 > frame len 160
20 packets captured
44 packets received by filter
0 packets dropped by kernel
zorro@pr5:~$
Я так понял tcpdump вылетает на некое ограничение и завершает работу. Пытался гуглить, но ничего конкретного не нашел.
Причем, если смотреть интерфейс lo, то тспдамп не вываливается:
zorro@pr5:~$ sudo tcpdump -i lo
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on lo, link-type EN10MB (Ethernet), capture size 96 bytes
Хотя,если со второй сессии ssh пустить пинг на 127.0.0.1:
zorro@pr5:~$ sudo tcpdump -i lo
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on lo, link-type EN10MB (Ethernet), capture size 96 bytes
tcpdump: pcap_loop: corrupted frame on kernel ring mac offset 94 + caplen 98 > frame len 160
0 packets captured
4 packets received by filter
0 packets dropped by kernel
Из-за чего вылетает tcpdump?