Multiple Interfaces, Not Seeing Requests

Adam Bishop Adam.Bishop at jisc.ac.uk
Tue Feb 7 00:16:29 CET 2017


On 6 Feb 2017, at 22:38, Matthew West <matthew.t.west at gmail.com> wrote:
> I'm happy to do the legwork for this one.  Can someone point me in the
> right direction for further troubleshooting?

RHEL/CentOS does not work well with multiple interfaces out of the box for some network configurations. You need to enable a few kernel settings to make it do the right thing.

It sounds like you may have one of the affected configurations.

The issue is detailed here:
  https://access.redhat.com/solutions/53031

You can confirm this by enabling martian logging using sysctl:
  net.ipv4.conf.*.log_martians=1

I wouldn't enable martial logging permanently; it's not necessary in normal operation and could cause your logging process  (rysslog/journald) to start discarding useful traffic.

Note that in my experience, setting default/all is not sufficient; you need to apply it to each individual interface explicitly. This may have changed in 7.3, or may not be the case if you're using an interface naming scheme that doesn't start with 'eno'.

If you're using firewalld, you also need to make sure that auxiliary interfaces are assigned to the correct zone.

Regards,

Adam Bishop

  gpg: E75B 1F92 6407 DFDF 9F1C  BF10 C993 2504 6609 D460

jisc.ac.uk

Jisc is a registered charity (number 1149740) and a company limited by guarantee which is registered in England under Company No. 5747339, VAT No. GB 197 0632 86. Jisc’s registered office is: One Castlepark, Tower Hill, Bristol, BS2 0JA. T 0203 697 5800.

Jisc Services Limited is a wholly owned Jisc subsidiary and a company limited by guarantee which is registered in England under company number 2881024, VAT number GB 197 0632 86. The registered office is: One Castle Park, Tower Hill, Bristol BS2 0JA. T 0203 697 5800.  




More information about the Freeradius-Users mailing list