[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Xen-users] finding the source VM of local ip

  • To: xen-users@xxxxxxxxxxxxx
  • From: Mofta7y <mofta7y@xxxxxxxxx>
  • Date: Thu, 25 Apr 2013 23:36:57 -0400
  • Delivery-date: Fri, 26 Apr 2013 03:38:28 +0000
  • List-id: Xen user discussion <xen-users.lists.xen.org>

Hi e very one

I am having an interesting issue.

it seems that one or more VMs users in an Xen server has configured a
local ip range for communication between VMs

We never gave our customers any local IPs and we give them public IPs only.

The issue is that those local IPs are flooding each other !! by TCP_SYN.
This in turn cause dom0 cpu usage to go high (si goes up to 36%) and as
a result we get a lot of lost packets and very high ping time

now my main issue is to find out which VMs are using these local IPs

I tried arping those ips and got their MAC address but this mac address
is not the mac address of any network interface in the server !!!

we are using bridged domu networking

anyone knows of any way to find which VMs are using these local IPs ?
Also if there is no way to find who is using them can we just prevent
them from communicating with each other through dom0 ?

why dom0 will almost stop handle traffic of domus when having a flood of
only 10K tcp connections (I know the number is not normal but i guess
dom0 should handle it especially dom0 has 6 dedicated cores)


Xen-users mailing list



Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.