Всем привет, проблема странная и не знаю куда рыть...
Есть организация в которой 2 сети.
1 сеть имеет доступ в инет
(vlan3 172.20.0.0/23)
, вторя
(vlan2 172.30.2.0/24)
нет.
Так надо, не спрашивайте зачем, да и вообще по наследству досталось.
Был у меня маршрутизатор на ubuntu и понадобилось мне его в VM перенести.
Перенес, все работае прекрасно, но не тут то было...
Так как компания это телекомпания, есть нужда писать мониторинг эфира.
так вот железка снимает SDI сигнал и пишет по расписанию в файл на файл сервер.
Ранее все было ок, но после того, как я перенес роутер в виртуалку начали создаваться
вот такие файлыЖелезка эта находится в приватной сети(172,30,2,22) и пишет на сервер на FreeNAS(172.20.0.35)
в сети с доступом в интернет.
Сначала грешил на FreeNAS потом попробовал присать на Windows машину в публичной сети и эффект такой же.
Пришется все просто в SMB шару.
Роутером между ними является собственно моя виртуальная машина на ubuntu и Cisco 3750(но этот просто несколько приватных разруливает) .
Подробно о конфигурации.
Гипервизор sle(по наследству):
агрегация 4 линка
bond0 Link encap:Ethernet HWaddr 00:1E:67:68:52:6A
UP BROADCAST RUNNING MASTER MULTICAST MTU:1500 Metric:1
RX packets:2421787603 errors:0 dropped:12 overruns:245 frame:0
TX packets:1814649010 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:2176906953482 (2076060.2 Mb) TX bytes:1936620854288 (1846905.5 Mb)
br0 Link encap:Ethernet HWaddr 00:1E:67:68:52:6A
inet addr:172.20.0.10 Bcast:172.20.1.255 Mask:255.255.254.0
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:43123657 errors:0 dropped:3526096 overruns:0 frame:0
TX packets:17252224 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:196430637901 (187330.8 Mb) TX bytes:2286143624 (2180.2 Mb)
# Влан для вырожденной сети до Cisco 3750
vlan98 Link encap:Ethernet HWaddr 00:1E:67:68:52:6A
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:20072844 errors:0 dropped:0 overruns:0 frame:0
TX packets:28301948 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:9384286028 (8949.5 Mb) TX bytes:5798127247 (5529.5 Mb)
# Интернет
vlan100 Link encap:Ethernet HWaddr 00:1E:67:68:52:6A
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:148662766 errors:0 dropped:22671 overruns:0 frame:0
TX packets:120230037 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:171726903777 (163771.5 Mb) TX bytes:29634773134 (28261.9 Mb)
далее конфиги на виртуалке, которая роутер.
eth0 Link encap:Ethernet HWaddr 52:54:00:51:0f:b3
inet addr:172.20.0.1 Bcast:172.20.1.255 Mask:255.255.254.0
inet6 addr: fe80::5054:ff:fe51:fb3/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:2332076 errors:0 dropped:120 overruns:0 frame:0
TX packets:1964348 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:1655087206 (1.6 GB) TX bytes:1899895539 (1.8 GB)
eth1 Link encap:Ethernet HWaddr 52:54:00:c3:af:07
inet addr:xxx.229.235.xxx Bcast:xxx.229.235.xxx Mask:255.255.255.240
inet6 addr: fe80::5054:ff:fec3:af07/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:1875299 errors:0 dropped:0 overruns:0 frame:0
TX packets:2082531 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:1700541512 (1.7 GB) TX bytes:2259249086 (2.2 GB)
eth2 Link encap:Ethernet HWaddr 52:54:00:6d:04:72
inet addr:192.168.98.1 Bcast:192.168.98.3 Mask:255.255.255.252
inet6 addr: fe80::5054:ff:fe6d:472/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1400 Metric:1
RX packets:202910 errors:0 dropped:0 overruns:0 frame:0
TX packets:326779 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:43242451 (43.2 MB) TX bytes:133681282 (133.6 MB)
eth0 = мост до br0(bond0) - сеть с доступом в интернет
eth1 = мост до vlan100(bond0) - интернет
eth2 = мост до vlan98(bond0) - приватная сеть
~$ netstat -nr
Таблица маршутизации ядра протокола IP
Destination Gateway Genmask Flags MSS Window irtt Iface
0.0.0.0 xxx.229.235.xxx 0.0.0.0 UG 0 0 0 eth1
xxx.229.235.xxx 0.0.0.0 255.255.255.240 U 0 0 0 eth1
172.20.0.0 0.0.0.0 255.255.254.0 U 0 0 0 eth0
172.30.2.0 192.168.98.2 255.255.255.0 UG 0 0 0 eth2
172.30.3.0 192.168.98.2 255.255.255.0 UG 0 0 0 eth2
172.30.4.0 192.168.98.2 255.255.255.0 UG 0 0 0 eth2
172.30.5.0 192.168.98.2 255.255.255.0 UG 0 0 0 eth2
172.30.7.0 172.20.0.21 255.255.255.0 UG 0 0 0 eth0
172.30.8.0 172.20.0.21 255.255.255.0 UG 0 0 0 eth0
172.30.9.0 172.20.0.21 255.255.255.0 UG 0 0 0 eth0
192.168.98.0 0.0.0.0 255.255.255.252 U 0 0 0 eth2
Фаерфол временно отключен вообще.
при прохождении трафика через маршрутизатор tcpdump вижу вот, что:
172.30.2.22.56880 > 172.20.0.35.445: Flags [.], cksum 0x122f (correct), seq 41640:43100, ack 3257, win 254, length 1460SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [.], cksum 0x42a5 (correct), seq 3257, ack 43100, win 1003, options [nop,nop,sack 1 {46020:47480}], length 0
172.30.2.22.56880 > 172.20.0.35.445: Flags [.], cksum 0x6614 (correct), seq 47480:48940, ack 3257, win 254, length 1460SMB-over-TCP packet:(raw data or continuation?)
172.30.2.22.56880 > 172.20.0.35.445: Flags [.], cksum 0x1b96 (correct), seq 48940:50400, ack 3257, win 254, length 1460SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [.], cksum 0x3cda (correct), seq 3257, ack 43100, win 1026, options [nop,nop,sack 1 {46020:48940}], length 0
172.20.0.35.445 > 172.30.2.22.56880: Flags [.], cksum 0x3726 (correct), seq 3257, ack 43100, win 1026, options [nop,nop,sack 1 {46020:50400}], length 0
172.30.2.22.3389 > 172.20.0.52.48030: Flags [P.], cksum 0x43f7 (correct), seq 13211:13712, ack 1, win 257, options [nop,nop,TS val 9311337 ecr 20596094], length 501
172.20.0.52.48030 > 172.30.2.22.3389: Flags [.], cksum 0x8e64 (correct), seq 1, ack 13712, win 2051, options [nop,nop,TS val 20596119 ecr 9311337], length 0
172.30.2.22.3389 > 172.20.0.52.48030: Flags [P.], cksum 0x682a (correct), seq 13712:14117, ack 1, win 257, options [nop,nop,TS val 9311347 ecr 20596119], length 405
172.20.0.52.48030 > 172.30.2.22.3389: Flags [.], cksum 0x8cac (correct), seq 1, ack 14117, win 2051, options [nop,nop,TS val 20596144 ecr 9311347], length 0
172.30.2.22.3389 > 172.20.0.52.48030: Flags [P.], cksum 0xe4c6 (correct), seq 14117:14762, ack 1, win 257, options [nop,nop,TS val 9311357 ecr 20596144], length 645
172.20.0.52.48030 > 172.30.2.22.3389: Flags [.], cksum 0x8a04 (correct), seq 1, ack 14762, win 2051, options [nop,nop,TS val 20596169 ecr 9311357], length 0
172.30.2.22.56880 > 172.20.0.35.445: Flags [.], cksum 0x4912 (correct), seq 43100:44560, ack 3257, win 254, length 1460SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [.], cksum 0x3189 (correct), seq 3257, ack 44560, win 1003, options [nop,nop,sack 1 {46020:50400}], length 0
172.30.2.22.56880 > 172.20.0.35.445: Flags [.], cksum 0xb3bd (correct), seq 50400:51860, ack 3257, win 254, length 1460SMB-over-TCP packet:(raw data or continuation?)
172.30.2.22.56880 > 172.20.0.35.445: Flags [.], cksum 0x4c3a (correct), seq 51860:53320, ack 3257, win 254, length 1460SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [.], cksum 0x2bbe (correct), seq 3257, ack 44560, win 1026, options [nop,nop,sack 1 {46020:51860}], length 0
172.20.0.35.445 > 172.30.2.22.56880: Flags [.], cksum 0x260a (correct), seq 3257, ack 44560, win 1026, options [nop,nop,sack 1 {46020:53320}], length 0
172.30.2.22.56880 > 172.20.0.35.445: Flags [.], cksum 0x11e2 (correct), seq 44560:46020, ack 3257, win 254, length 1460SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [.], cksum 0x7f91 (correct), seq 3257, ack 53320, win 889, length 0
172.30.2.22.56880 > 172.20.0.35.445: Flags [P.], cksum 0xb972 (correct), seq 53320:54564, ack 3257, win 254, length 1244SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [.], cksum 0x7a3f (correct), seq 3257, ack 54564, win 1007, length 0
172.20.0.35.445 > 172.30.2.22.56880: Flags [P.], cksum 0x87c0 (correct), seq 3257:3341, ack 54564, win 1025, length 84SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [P.], cksum 0xf66c (correct), seq 3341:3469, ack 54564, win 1026, length 128SMB-over-TCP packet:(raw data or continuation?)
172.30.2.22.56880 > 172.20.0.35.445: Flags [.], cksum 0x7c5d (correct), seq 54564, ack 3469, win 253, length 0
172.30.2.22.56880 > 172.20.0.35.445: Flags [P.], cksum 0x414d (correct), seq 54564:54656, ack 3469, win 253, length 92SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [.], cksum 0x78fd (correct), seq 3469, ack 54656, win 1025, length 0
172.30.2.22.56880 > 172.20.0.35.445: Flags [P.], cksum 0x7985 (correct), seq 54656:54900, ack 3469, win 253, length 244SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [P.], cksum 0xf490 (correct), seq 3469:3597, ack 54656, win 1026, length 128SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [.], cksum 0x778c (correct), seq 3597, ack 54900, win 1022, length 0
172.20.0.35.445 > 172.30.2.22.56880: Flags [P.], cksum 0x1bd0 (correct), seq 3597:3841, ack 54900, win 1026, length 244SMB-over-TCP packet:(raw data or continuation?)
172.30.2.22.56880 > 172.20.0.35.445: Flags [.], cksum 0x799a (correct), seq 54900, ack 3841, win 252, length 0
172.30.2.22.56880 > 172.20.0.35.445: Flags [P.], cksum 0x8cf9 (correct), seq 54900:55120, ack 3841, win 252, length 220SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [.], cksum 0x75bb (correct), seq 3841, ack 55120, win 1023, length 0
172.30.2.22.56880 > 172.20.0.35.445: Flags [P.], cksum 0x53bf (correct), seq 55120:55612, ack 3841, win 252, length 492SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [P.], cksum 0x612e (correct), seq 3841:4029, ack 55120, win 1026, length 188SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [.], cksum 0x7318 (correct), seq 4029, ack 55612, win 1018, length 0
172.20.0.35.445 > 172.30.2.22.56880: Flags [P.], cksum 0x9bfb (correct), seq 4029:4113, ack 55612, win 1026, length 84SMB-over-TCP packet:(raw data or continuation?)
172.30.2.22.56880 > 172.20.0.35.445: Flags [.], cksum 0x75c3 (correct), seq 55612, ack 4113, win 251, length 0
172.30.2.22.56880 > 172.20.0.35.445: Flags [P.], cksum 0x47d3 (correct), seq 55612:55704, ack 4113, win 251, length 92SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [.], cksum 0x7261 (correct), seq 4113, ack 55704, win 1025, length 0
172.20.0.35.445 > 172.30.2.22.56880: Flags [P.], cksum 0xe9f4 (correct), seq 4113:4241, ack 55704, win 1026, length 128SMB-over-TCP packet:(raw data or continuation?)
172.30.2.22.56880 > 172.20.0.35.445: Flags [P.], cksum 0x8538 (correct), seq 57888:57980, ack 4241, win 256, length 92SMB-over-TCP packet:(raw data or continuation?)
172.30.2.22.56880 > 172.20.0.35.445: Flags [P.], cksum 0x6982 (correct), seq 57980:58224, ack 4241, win 256, length 244SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [.], cksum 0xb619 (correct), seq 4241, ack 55704, win 1026, options [nop,nop,sack 1 {57888:57980}], length 0
172.20.0.35.445 > 172.30.2.22.56880: Flags [.], cksum 0xb525 (correct), seq 4241, ack 55704, win 1026, options [nop,nop,sack 1 {57888:58224}], length 0
172.30.2.22.3389 > 172.20.0.52.48030: Flags [P.], cksum 0x6b3d (correct), seq 14762:15535, ack 1, win 257, options [nop,nop,TS val 9311367 ecr 20596169], length 773
172.20.0.52.48030 > 172.30.2.22.3389: Flags [.], cksum 0x86dc (correct), seq 1, ack 15535, win 2051, options [nop,nop,TS val 20596194 ecr 9311367], length 0
172.30.2.22.3389 > 172.20.0.52.48030: Flags [P.], cksum 0x7a9c (correct), seq 15535:16868, ack 1, win 257, options [nop,nop,TS val 9311377 ecr 20596194], length 1333
172.20.0.52.48030 > 172.30.2.22.3389: Flags [.], cksum 0x8184 (correct), seq 1, ack 16868, win 2051, options [nop,nop,TS val 20596219 ecr 9311377], length 0
172.30.2.22.56880 > 172.20.0.35.445: Flags [.], cksum 0x5e68 (correct), seq 55704:57164, ack 4241, win 256, length 1460SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [.], cksum 0xaf88 (correct), seq 4241, ack 57164, win 1003, options [nop,nop,sack 1 {57888:58224}], length 0
172.30.2.22.56880 > 172.20.0.35.445: Flags [P.], cksum 0xbe0d (correct), seq 57164:58224, ack 4241, win 256, length 1060SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [.], cksum 0x6818 (correct), seq 4241, ack 58224, win 1010, length 0
172.20.0.35.445 > 172.30.2.22.56880: Flags [P.], cksum 0xf2f1 (correct), seq 4241:4325, ack 58224, win 1021, length 84SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [P.], cksum 0xdd4c (correct), seq 4325:4453, ack 58224, win 1022, length 128SMB-over-TCP packet:(raw data or continuation?)
172.30.2.22.56880 > 172.20.0.35.445: Flags [.], cksum 0x6a37 (correct), seq 58224, ack 4453, win 255, length 0
172.20.0.35.445 > 172.30.2.22.56880: Flags [P.], cksum 0x6998 (correct), seq 4453:4697, ack 58224, win 1026, length 244SMB-over-TCP packet:(raw data or continuation?)
172.30.2.22.56880 > 172.20.0.35.445: Flags [P.], cksum 0x7ca3 (correct), seq 58224:58444, ack 4697, win 254, length 220SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [.], cksum 0x6567 (correct), seq 4697, ack 58444, win 1023, length 0
172.30.2.22.56880 > 172.20.0.35.445: Flags [P.], cksum 0xa770 (correct), seq 58444:59124, ack 4697, win 254, length 680SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [.], cksum 0x62c7 (correct), seq 4697, ack 59124, win 1015, length 0
172.20.0.35.445 > 172.30.2.22.56880: Flags [P.], cksum 0xbf33 (correct), seq 4697:4885, ack 59124, win 1015, length 188SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [P.], cksum 0xc8ea (correct), seq 4885:4969, ack 59124, win 1026, length 84SMB-over-TCP packet:(raw data or continuation?)
172.30.2.22.56880 > 172.20.0.35.445: Flags [.], cksum 0x64b1 (correct), seq 59124, ack 4969, win 253, length 0
172.30.2.22.56880 > 172.20.0.35.445: Flags [P.], cksum 0x242c (correct), seq 59124:59216, ack 4969, win 253, length 92SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [.], cksum 0x6151 (correct), seq 4969, ack 59216, win 1025, length 0
172.20.0.35.445 > 172.30.2.22.56880: Flags [P.], cksum 0xd2e4 (correct), seq 4969:5097, ack 59216, win 1026, length 128SMB-over-TCP packet:(raw data or continuation?)
172.30.2.22.56880 > 172.20.0.35.445: Flags [P.], cksum 0xb2a7 (correct), seq 59216:59308, ack 5097, win 253, length 92SMB-over-TCP packet:(raw data or continuation?)
172.30.2.22.56880 > 172.20.0.35.445: Flags [P.], cksum 0x5afd (correct), seq 59308:59552, ack 5097, win 253, length 244SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [.], cksum 0x6075 (correct), seq 5097, ack 59308, win 1025, length 0
172.20.0.35.445 > 172.30.2.22.56880: Flags [.], cksum 0x5f85 (correct), seq 5097, ack 59552, win 1021, length 0
172.20.0.35.445 > 172.30.2.22.56880: Flags [P.], cksum 0xd018 (correct), seq 5097:5225, ack 59552, win 1022, length 128SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [P.], cksum 0xce1d (correct), seq 5225:5469, ack 59552, win 1026, length 244SMB-over-TCP packet:(raw data or continuation?)
172.30.2.22.56880 > 172.20.0.35.445: Flags [.], cksum 0x6113 (correct), seq 59552, ack 5469, win 251, length 0
172.30.2.22.56880 > 172.20.0.35.445: Flags [P.], cksum 0x6e72 (correct), seq 59552:59772, ack 5469, win 251, length 220SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [.], cksum 0x5d33 (correct), seq 5469, ack 59772, win 1023, length 0
172.20.0.35.445 > 172.30.2.22.56880: Flags [P.], cksum 0x0da9 (correct), seq 5469:5657, ack 59772, win 1026, length 188SMB-over-TCP packet:(raw data or continuation?)
172.30.2.22.56880 > 172.20.0.35.445: Flags [P.], cksum 0xc8dd (correct), seq 61392:61484, ack 5657, win 251, length 92SMB-over-TCP packet:(raw data or continuation?)
172.20.0.35.445 > 172.30.2.22.56880: Flags [.], cksum 0x854d (correct), seq 5657, ack 59772, win 1026, options [nop,nop,sack 1 {61392:61484}], length 0
172.30.2.22.3389 > 172.20.0.52.48030: Flags [P.], cksum 0x9190 (correct), seq 18633:19662, ack 1, win 257, options [nop,nop,TS val 9311397 ecr 20596219], length 1029
172.20.0.52.48030 > 172.30.2.22.3389: Flags [.], cksum 0xa7c9 (correct), seq 1, ack 16868, win 2051, options [nop,nop,TS val 20596269 ecr 9311377,nop,nop,sack 1 {18633:19662}], length 0
Ну вот как то так, даже хз куда рыть...