- 论坛徽章:
- 0
|
用linux做的代理服务器,近来常出现网内无法通信的情况,在linux代理服务器上执行tcpdump出现如下信息,请问这些信息说明了什么情况?我该如何处理?
[root@zust-proxy root]# tcpdump -f|more
tcpdump: listening on eth0
13:51:31.631089 202.101.165.250.http >; 201.90.217.27.56007: . 1683655370:1683656
818(144 ack 3195576620 win 65081 <nop,nop,timestamp 19779281 5417223>; (DF)
13:51:31.633137 201.90.217.27>; 210.42.53.176: icmp: echo request
13:51:31.634105 201.90.217.27>; 172.15.145.17: icmp: echo request
13:51:31.634119 201.90.217.27.32821 >; 211.90.216.129.domain: 29693+ PTR? 67.227
.90.211.in-addr.arpa. (44) (DF)
13:51:31.635457 arp who-has 172.16.75.161 tell 172.16.16.61
13:51:31.635954 211.90.216.129.domain >; 201.90.217.27.32821: 29693 NXDomain 0/1
/0 (103)
13:51:31.639347 arp who-has 172.16.154.49 tell 172.16.16.25
13:51:31.640202 201.90.217.27>; 202.208.209.216: icmp: echo request
13:51:31.642674 201.90.217.27>; 210.42.53.177: icmp: echo request
13:51:31.643879 arp who-has 172.16.4.236 tell 172.16.253.253
13:51:31.648067 arp who-has 172.16.4.237 tell 172.16.253.253
13:51:31.648292 201.90.217.27>; 172.15.145.18: icmp: echo request
13:51:31.650456 201.90.217.27.1151 >; 61.153.8.50.4230: . ack 3699920800 win 8760
(DF)
13:51:31.651077 arp who-has 172.16.75.162 tell 172.16.16.61
13:51:31.652638 201.90.217.27>; 210.42.53.178: icmp: echo request
13:51:31.654985 arp who-has 172.16.154.50 tell 172.16.16.25
13:51:31.656195 201.90.217.27>; 61.40.15.133: icmp: echo request
13:51:31.657797 218.25.10.19.1806 >;201.90.217.27.1454: . 3289756086:3289757546(
1460) ack 1807390219 win 65535 (DF)
13:51:31.657914 arp who-has 172.16.4.238 tell 172.16.253.253
13:51:31.659016 218.25.10.19.1806 >; 201.90.217.27.1454: . 1460:2920(1460) ack 1
win 65535 (DF)
13:51:31.659910 218.25.10.19.1806 >; 201.90.217.27.1454: P 2920:4096(1176) ack 1
win 65535 (DF)
13:51:31.662718 201.90.217.27>; 210.42.53.179: icmp: echo request
13:51:31.662732 201.90.217.27.1454 >; 218.25.10.19.1806: . ack 2920 win 17520 (DF
)
13:51:31.663941 201.90.217.27>; 172.15.145.19: icmp: echo request
13:51:31.663521 202.101.165.250.http >; 201.90.217.27.56007: . 1448:2896(144 ac
k 1 win 65081 <nop,nop,timestamp 19779281 5417240>; (DF)
13:51:31.664022 201.90.217.27.56007 >; 202.101.165.250.http: . ack 2896 win 63712
<nop,nop,timestamp 5417266 19779281>; (DF)
13:51:31.664749 202.101.165.250.http >; 201.90.217.27.56007: . 2896:4344(144 ac
k 1 win 65081 <nop,nop,timestamp 19779281 5417240>; (DF)
13:51:31.666715 arp who-has 172.16.75.163 tell 172.16.16.61
13:51:31.667921 arp who-has 172.16.4.239 tell 172.16.253.253
13:51:31.668562 202.101.165.250.http >; 201.90.217.27.56007: . 4344:5792(144 ac
k 1 win 65081 <nop,nop,timestamp 19779281 5417242>; (DF)
13:51:31.668612 201.90.217.27.56007 >; 202.101.165.250.http: . ack 5792 win 63712
<nop,nop,timestamp 5417268 19779281>; (DF)
13:51:31.669722 202.101.165.250.http >; 201.90.217.27.56007: . 5792:7240(144 ac
k 1 win 65081 <nop,nop,timestamp 19779281 5417242>; (DF)
13:51:31.670565 arp who-has 172.16.154.51 tell 172.16.16.25
13:51:31.672646 201.90.217.27>; 210.42.53.180: icmp: echo request
13:51:31.674146 201.90.217.27>; 61.72.125.20: icmp: echo request
13:51:31.675572 202.101.165.250.http >; 201.90.217.27.56007: . 7240:8688(144 ac
k 1 win 65081 <nop,nop,timestamp 19779282 5417246>; (DF)
13:51:31.675624 201.90.217.27.56007 >; 202.101.165.250.http: . ack 8688 win 63712
<nop,nop,timestamp 5417272 19779281>; (DF)
13:51:31.676795 202.101.165.250.http >; 201.90.217.27.56007: . 8688:10136(144 a
ck 1 win 65081 <nop,nop,timestamp 19779282 5417246>; (DF)
13:51:31.678004 202.101.165.250.http >; 201.90.217.27.56007: . 10136:11584(144
ack 1 win 65081 <nop,nop,timestamp 19779282 5417247>; (DF)
13:51:31.678050 201.90.217.27.56007 >; 202.101.165.250.http: . ack 11584 win 6371
2 <nop,nop,timestamp 5417273 19779282>; (DF)
13:51:31.678627 arp who-has 172.16.4.240 tell 172.16.253.253
13:51:31.679296 202.101.165.250.http >; 201.90.217.27.56007: . 11584:13032(144
ack 1 win 65081 <nop,nop,timestamp 19779282 5417247>; (DF)
13:51:31.680502 202.101.165.250.http >; 201.90.217.27.56007: . 13032:14480(144
ack 1 win 65081 <nop,nop,timestamp 19779282 5417249>; (DF)
13:51:31.680551 201.90.217.27.56007 >; 202.101.165.250.http: . ack 14480 win 6371
2 <nop,nop,timestamp 5417274 19779282>; (DF)
13:51:31.681721 202.101.165.250.http >; 201.90.217.27.56007: . 14480:15928(1448)
ack 1 win 65081 <nop,nop,timestamp 19779282 5417249>; (DF)
13:51:31.683222 201.90.217.27>; 210.42.53.181: icmp: echo request
13:51:31.682284 arp who-has 172.16.75.164 tell 172.16.16.61
13:51:31.686267 201.90.217.27 >; 172.15.145.20: icmp: echo request
13:51:31.686558 arp who-has 172.16.154.52 tell 172.16.16.25
13:51:31.687155 201.90.217.27>; 200.83.43.9: icmp: echo request
13:51:31.687999 arp who-has 172.16.4.241 tell 172.16.253.253
13:51:31.692752 201.90.217.27>; 210.42.53.182: icmp: echo request
13:51:31.695226 201.90.217.27>; 172.15.145.21: icmp: echo request
13:51:31.683222 201.90.217.27>; 210.42.53.181: icmp: echo request
13:51:31.682284 arp who-has 172.16.75.164 tell 172.16.16.61
13:51:31.686267 201.90.217.27>; 172.15.145.20: icmp: echo request
13:51:31.686558 arp who-has 172.16.154.52 tell 172.16.16.25
13:51:31.687155 201.90.217.27>; 200.83.43.9: icmp: echo request
13:51:31.687999 arp who-has 172.16.4.241 tell 172.16.253.253
13:51:31.692752 201.90.217.27>; 210.42.53.182: icmp: echo request
13:51:31.695226 201.90.217.27>; 172.15.145.21: icmp: echo request
13:51:31.698000 arp who-has 172.16.75.165 tell 172.16.16.61
13:51:31.698058 arp who-has 172.16.4.242 tell 172.16.253.253
13:51:31.702763 201.90.217.27>; 210.42.53.183: icmp: echo request
13:51:31.701824 arp who-has 172.16.154.53 tell 172.16.16.25
13:51:31.703526 201.90.217.27>; 210.184.166.216: icmp: echo request
13:51:31.708298 arp who-has 172.16.4.243 tell 172.16.253.253
13:51:31.710728 201.90.217.27>; 172.15.145.22: icmp: echo request
13:51:31.712784 201.90.217.27>; 210.42.53.184: icmp: echo request |
|