Excess search traffic upon login

Greetings,
I've noticed recently that when any of my users logs in (all are now LDAP authenticated), the access log shows a LOT of searching going on during that transaction. For example, if I log into a host, the access log will show not only the transaction of verifying my uid, and my shadow info, but it seems to want to list ALL of the netgroups that my uid happens to belong to. The reason this is a problem is that each host (or group of type of hosts) has a specific netgroup associated with it, and my assumption is that after verifying my username/pw info, it would just look at the netgroup name in /etc/passwd and see if I'm a part of that netgroup, and if so, allow me in, and if not, deny me access. Instead, the entire list of netgroups that my username is a member of is run through before allowing me into the host.
The reason this even became evident is that my access logs grow at rediculous rates. Fortunately I've configured logging and such to roll logs and delete them properly, but I really don't know why all of the other data is returned. It's not relevant to the host being logged into, and it occurs to me that it's a mild security problem since that traffic is visible over the network (I'm not using TLS at the moment) and shows the netgroups that I'm a member of (nevermind that I'm not sure how this would benefit an attacker).
So, does anyone know how to cut this down? It seems like an awful waste of time/bandwidth, and also possibly a waste of connections and other resources on the directory server.
TIA,
Patrick

Also, have you tried doing an 'ls -l' against a
directory with files owned by different users? I had
a test directory with 250 files, each owned by a
different user. When using netgroup to define users
(via @netgroup in /etc/passwd and compat in
nsswitch.conf) the performance was terribly slow,
possibly due to nested netgroups.Roger,
If you enable passwd (and group, if you want) caching via nscd, you'll see that the performance for "ls -l" like you're describing above, will improve dramatically. I was experiencing the same problem, and I found that what was dragging it down was the uid->username (and possibly gid->group) translation. Once I enabled caching the performance immediately improved.
I also noted that before enabling nscd for passwd and group that my slapd process on my primary DS server was soaking up between 80 and 100% cpu, and my server was being hammered by requests (the access log was logging >5MB/min). Once nscd was implemented the CPU went down dramatically (to <5%), and my access logs are loggging at about 1MB/min now (but that's due to the excess netgroup stuff, which is why I started this thread :P )
Patrick

Similar Messages

  • I have a new IMAC 5k running Yosemite and when I log in I am asked a whole series of questions as to what keychain can access. How can I authorise all of these to be available upon login? Items concerned are such as "Talagent", "Messages agent" etc

    I have a new IMAC 5k running Yosemite and when I log in I am asked a whole series of questions as to what keychain can access. How can I authorise all of these to be available upon login? Items concerned are such as "Talagent", "Messages agent" etc

    Back up all data before proceeding.
    Launch the Keychain Access application in any of the following ways:
    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
    ☞ Open LaunchPad and start typing the name.
    Select the login keychain from the list on the left side of the Keychain Access window. If your default keychain has a different name, select that.
    If the lock icon in the top left corner of the window shows that the keychain is locked, click to unlock it. You'll be prompted for the keychain password, which is the same as your login password, unless you've changed it.
    Right-click or control-click the login entry in the list. From the menu that pops up, select
              Change Settings for Keychain "login"
    In the sheet that opens, uncheck both boxes, if not already unchecked.
    From the menu bar, select
              Keychain Access ▹ Preferences... ▹ First Aid
    There are four checkboxes in the window that opens. Check all of them. if they're not already checked. Close the window.
    Select
              Keychain Access ▹ Keychain First Aid
    from the menu bar and repair the keychain. Quit Keychain Access.
    If you use iCloud Keychain, open the iCloud preference pane and uncheck the Keychain box. You'll be prompted to delete the local iCloud keychain. Confirm. Then re-check the box. Follow one of the procedures described in this support article to set up iCloud Keychain on an additional device.

  • Excessive ICMP traffic on server

    Hello,
    I am experiencing excessive ICMP traffic on all my Netware 6.5 SP6
    servers. This ICMP traffic originates at the server; not from a
    workstation. Tried to search KB but no luck. I want to know if any
    netware products rely on ICMP communication and if I can disable ICMP at
    the server console. Currently we have ACLs on all core switches denying
    ICMP traffic. However, all the traffic on the network itself is causing
    congestion.
    To give you an idea of the problem, this AM I tried to download a 1MB file
    from a remote site and it took an ave. of 5 min. I then, powered off the
    NW server, checked the logs on core switch, ICMP traffic literally
    disappeared, and tried the same download again; this time only taking 40
    sec.
    Please help! This is affecting my network drastically!!!

    There are different scenarios in which ICMP packets copuld be generated.
    You should really capture the ICMP packets to see what is really going on.
    Some possible cases are:
    - ICMP packets used for costing (e.g. determinining the distance of other
    servers to see which server might be the best to talk to)
    - ICMP replies in case of error conditions (can't fragmnet and no such
    protocol replies)
    while filtering ICMP traffic in itself is a good idea, blankly turning it
    off completely is generally a very bad idea as some communications really
    need ICMP and perform badly without out (for instance MTU detection will
    not work without ICMP)
    Marcel Cox (using XanaNews 1.18.1.6)

  • Empty ZENworks Window(NAL) upon login-April 2013 follow-up

    I know this is from an older post back on April 9, 2013, but I am still experiencing the same issue. I have troubleshooted this to no end since then, but have not come up with a solution yet. Since the original post, I have upgraded my ZENworks servers to 11.2.3a and have done the same on my clients. Sometimes the only solution I can find is to uninstall and re-install the ZENworks agent. I can't seem to find what is causing this as the issue is sporadic and not occurring everywhere.
    Any ideas? I have copied the original post below.
    Thanks.
    Scott
    There is a cache corruption issue that I am also experiencing that I believe
    MU2 and now 3a resolves. I have had to do exactly what you are doing.
    waiting for the early adapters to shake out the current SP before I install.
    "sleonard24" wrote in message
    news:[email protected]..
    I am having periodic issues in which users report that the ZENworks
    Application Window is empty upon login. The bundles are shortcuts to run
    ..exe files that are installed on the workstations, web url shortcuts,
    shortcuts to run .exe files on a network server. These bundles will not
    show up when there are or are not requirements for the bundle and does
    not depend on the user that logs in. I have the shortcut for the
    ZENworks Application Window in the "Startup" folder for all user in
    WinXP and in the c:\programdata\microsoft\windows\start
    menu\programs\startup .
    What I have found that works to get the applications to re-appear for
    the users is to re-register the computer with - zac reg -g
    https://servername .
    The particulars:
    ZENworks version-11 sp2
    ZENworks servers - four(4) primary servers; Windows 2008R2 sp1
    ZENworks database - Windows 2008R2 sp1; SQL 2008R2 sp2
    workstation OS - Windows 7 or WindowsXP
    Windows 2008R2 AD domain
    Any thoughts on why this happens?
    Thank you.
    Scott

    sleonard24 wrote:
    > I know this is from an older post back on April 9, 2013, but I am
    > still experiencing the same issue. I have troubleshooted this to no
    > end since then, but have not come up with a solution yet. Since the
    > original post, I have upgraded my ZENworks servers to 11.2.3a and
    > have done the same on my clients. Sometimes the only solution I can
    > find is to uninstall and re-install the the ZENworks agent. I can't
    > seem to find what is causing this as the issue is sporadic and not
    > occurring everywhere.
    This sounds like it could be the problem we had with earlier ZCM
    versions that the local db cache would get corrupt in the ZEN agent,
    causing the machine to appear as if it's unmanaged. To help identify
    if you might still be experiencing this, the next time this happens
    would you do a zac cc followed by a zac ref on the machine and see if
    the bundles come back?
    Your world is on the move. http://www.novell.com/mobility/
    We know what your world looks like. http://www.novell.com/yourworld/

  • Make CAD agents to go ready state upon login

    hi all,
    hope someone can help. running uccx 8.0.   when agents log into CAD, it always put them in not ready state. is there a way to make them go ready right away upon login.
    thanks
    vijay           

    Hi Vijay,
    Agent State Action
    An Agent State action enables you to select an agent state to associate with an event.
    Agent State actions can be associated only with Answered and Dropped events. The
    only valid agent states are Login, Logout, Ready, Not Ready, and Work.
    To set up an Agent State action:
    1.Set up a new action. See “Adding a New Action” on page 98. The Select Action window appears.
    2.Select the Agent State tab, and then click New. The Agent State Action Setup box appears (Figure 49).
    3.Enter a name for the action, select the agent state control from the drop-down list, and then click OK
    Please refer the CDA guide for more information,
    http://www.cisco.com/en/US/docs/voice_ip_comm/cust_contact/contact_center/crs/express_8_5/user/guide/cda85ccxug-cm.pdf
    Hope this helps.
    Anand
    Please rate helpful posts by clicking on the stars below the right answers !!

  • Filtering entries in BP search based upon user

    Hi
    We are trying to filter out results shown in BP search, based upon users. For that we are trying to follow steps mentioned in IMG
    SPRO->IMG-> Customer Relationship Management -> CRM Cross-Application
    Components -> Generic Interaction Layer/Object Layer ->
    Component-Specific Settings -> Extend Object Model for Business Partner
    The field(region) we are using is already present in structure CRMST_HEADER_SEARCH_BUIL and as per my understanding we will be using method Adjust_Result_Table.
    But still I am not able to resolve it. Please help me in this regard.
    Thanx & Regards
    Hits

    Hi,
    The object that we work with at 2007:
    BuilHeaderSearchNew
    and not BuilHeader like at the last version
    so, we have to implement CL_BUPA_IL_HEADER_SEARCH and not CL_BUIL_HEADER
    1. Create :
    ZCL_BUPA_IL_HEADER_SEARCH
    with superclass:
    CL_BUPA_IL_HEADER_SEARCH
    2. At customizing:
    SPRO->CRM->Cross Application components->Generic Interaction Layer/Object Layer->component specific setting ->Extend Object Model for Business Partner
    add:
    External Object Name - BuilHeaderSearchNew
    Implementation Class - ZCL_BUPA_IL_HEADER_SEARCH
    Nou you can use this method for changing the result:
    ZCL_BUPA_IL_HEADER_SEARCH ->GET_RESULT_TABLE
    good luck
    ayelet

  • Openbox refuses to boot upon login no matter what I try [SOLVED]

    I've followed so far a few different guides and recommendations in how to get openbox to launch upon login/boot, needless to say I've just about given up the venture.
    Note: I'm not running GNOME or KDE at all, I'm attempting to use Openbox by itself without any other WM's getting in the way.
    .xinitrc
    #!/bin/sh
    # ~/.xinitrc
    # Executed by startx
    #Window managers
    exec openbox-session
    autostart.sh
    #autostart.sh executes before .xinitrc, stuff that is to launch first
    #starts here
    # Environment variables set here are passed to openbox
    . $GLOBALAUTOSTART
    # The below runs after Openbox
    (sleep 3 $$ conky) &
    (sleep 5 && sudo nitrogen --restore) &
    (sleep 9 && sudo tint2) &
    Please excuse any above typos in the code listed above, I'm transposing it onto another computer.
    Thanks for looking!
    Last edited by kzersatz (2010-02-26 05:03:44)

    Thanks all of you
    @Anonymous_user: Solved the issue!
    added to my ~/.bash_profile and it solved the issue
    if [[ -z "$DISPLAY" ]] && [[ $(tty) = /dev/tty1 ]]; then
    xinit
    logout
    fi

  • Can't get application to start upon login

    Hello everyone!
    I'm using Gnome 3, and I am trying to get an application to run upon login. I've created the following desktop entry for it:
    [Desktop Entry]
    Type=Application
    Name=xflux
    Exec=/usr/bin/xflux -l 52.0 -g 5.0
    I've tried saving in ~/.config/autostart and in /usr/share/gnome/autostart, but neither seem to work. The command "/usr/bin/xflux -l 52.0 -g 5.0" executes just fine when invoked in from the terminal, and other desktop entries in /usr/share/gnome/autostart start just fine. Do any of you have a clue of what I'm doing wrong?

    I never had much luck with f.lux on linux. I don't know exactly what the problem is here, it looks okay.
    If you don't find a solution, I recommend using redshift. It achieves the same end as f.lux. You can find it in the official repos here.
    Edit: in your last post I assume you mean xflux, as that is the name of the executable.
    Last edited by nullified (2015-02-25 20:25:09)

  • Howto open a webpage with Firefox upon login on Mac?

    I'd like to open a webpage upon login on Mac.
    What i did so far:
    - I saved the url location from firefox onto my desktop. It's a .webloc file. Firefox can open this file at this point.
    - Firefox is set up as my default browser.
    - Added the webloc-file to my startup list on my Mac useraccount.
    Then i try. The website will open, but it uses Safari instead of Firefox (firefox is still default browser).
    Next thing it tried:
    - Associate .webloc files to open with Firefox by default instead of Safari (that appeared to be the problem).
    - PROBLEM: Mac/Firefox won't let me use Firefox as default application to run webloc files with.
    How to solve this?

    Hello Zeror, you have firefox as default browser in firefox preferences only ?
    or you have it already and in your safari preferences ? check from Safari : menu > Preferences > General > Default web browser > firefox .
    you can try the above if you haven't already.
    thank you

  • Dashboard loads upon login so it's ready to go upon first use

    Isn't there some kind of Apple app that loads the Dashboard upon login? I recall seeing a 'DashboardClient' item in my Login Items when I installed Tiger on my G3 iMac. Since my Login Items list was so long I deleted the DashboardClient among others.
    Now when I activate Dashboard for the first time, it takes a few minutes to load everything.
    I have used File Buddy and Spotlight to look for a DashboardClient app or process or something to no avail.
    I know I have seen others suggesting 3rd party apps to correct this issue but I'd rather use an already provided Apple solution if it's really there.
    Any thoughts?
    iMac DV SE (Summer 2001)   Mac OS X (10.4.7)   1GB RAM; 500GB Ext FW HD; Pioneer DVR-111 OD

    There is a dashboard application in your applications
    folder.
    Thanks for the reminder!
    Actually, I tried that and added it into my Login Items. When I did so and logged in, it actually launched dashboard so when my login finished, Dashboard was visible. It did accomplish loading Dashboard but I was hoping for a way to do it without having to tell it to go away each time I login.
    Other thoughts?

  • Weblogic 6.1.2 Console Exits Upon Login

    I've seen several posts about the Weblogic Console immediately exiting
    upon login, but none of these posts have a solution to the problem.
    After grappling with this issue myself, I've found that the problem
    seems to stem from a having the wrong JRE plugin. For instance, in
    6.1.2, I had installed the Java Runtime Edition 1.3.1_02 plugin. After
    this installation, my browsers would simply close after logging into the
    console. When I backed the plugin out to JRE 1.3.1, the problem went away.
    Hope this saves you some time.
    - Ryan

    Hi guys,
    As Ryan pointed, the problem is because of the JRE incompatibility...
    Try to install the JRE 1.4 & above which will solve the issue.

  • Trouble connecting to a shared resource upon login

    I updated my server/client system this summer and I haven't worked out all the bugs yet.
    My wgm server is running Snow Leopard. All student accounts and documents are on the Snow Leopard server. I have another server running Leopard. Some shared resources (program data storage, etc.) are on the Leopard server.
    I want a 1st grader to log in (10.4 client) and have it automatically connect to the share point on the Leopard server. I have not duplicated the student accounts on the Leopard server because I don't want to maintain two user databases. If there was a way to get the Leopard server to draw the user database from the Snow Leopard server, I think that would solve my problem.
    As it is, because the Leopard server doesn't have an account for that student, the share point isn't connected to upon login. No share point mounted, program won't run.
    I'd be happy if there was a way to make the share point mount automatically with a generic login like "mrshare" and a password.
    So what do I do? Do I have to shift all my shared resources to the Snow Leopard server and burden it more?
    Thanks for your help.

    Assuming that your username is "acurotto", have you tried connecting to smb://tako/acurotto?

  • [SOLVED] How to disable "No mail." message upon login?

    This one's really stumping me. I disable the mail message a few months ago by creating a .hushlogin file in my home directory. That did the trick. Now, I am seeing the message again, and I don't know why. .hushlogin still exists in my home directory. Here's my /etc/login.defs:
    # /etc/login.defs - Configuration control definitions for the login package.
    # Three items must be defined: MAIL_DIR, ENV_SUPATH, and ENV_PATH.
    # If unspecified, some arbitrary (and possibly incorrect) value will
    # be assumed. All other items are optional - if not specified then
    # the described action or option will be inhibited.
    # Comment lines (lines beginning with "#") and blank lines are ignored.
    # Modified for Linux. --marekm
    # Delay in seconds before being allowed another attempt after a login failure
    FAIL_DELAY 3
    # Enable display of unknown usernames when login failures are recorded.
    LOG_UNKFAIL_ENAB no
    # Enable logging of successful logins
    LOG_OK_LOGINS no
    # Enable "syslog" logging of su activity - in addition to sulog file logging.
    # SYSLOG_SG_ENAB does the same for newgrp and sg.
    SYSLOG_SU_ENAB yes
    SYSLOG_SG_ENAB yes
    # If defined, either full pathname of a file containing device names or
    # a ":" delimited list of device names. Root logins will be allowed only
    # upon these devices.
    CONSOLE /etc/securetty
    #CONSOLE console:tty01:tty02:tty03:tty04
    # If defined, all su activity is logged to this file.
    #SULOG_FILE /var/log/sulog
    # If defined, file which maps tty line to TERM environment parameter.
    # Each line of the file is in a format something like "vt100 tty01".
    #TTYTYPE_FILE /etc/ttytype
    # If defined, the command name to display when running "su -". For
    # example, if this is defined as "su" then a "ps" will display the
    # command is "-su". If not defined, then "ps" would display the
    # name of the shell actually being run, e.g. something like "-sh".
    SU_NAME su
    # *REQUIRED*
    # Directory where mailboxes reside, _or_ name of file, relative to the
    # home directory. If you _do_ define both, MAIL_DIR takes precedence.
    # QMAIL_DIR is for Qmail
    #QMAIL_DIR Maildir
    MAIL_DIR /var/spool/mail
    # If defined, file which inhibits all the usual chatter during the login
    # sequence. If a full pathname, then hushed mode will be enabled if the
    # user's name or shell are found in the file. If not a full pathname, then
    # hushed mode will be enabled if the file exists in the user's home directory.
    HUSHLOGIN_FILE .hushlogin
    #HUSHLOGIN_FILE /etc/hushlogins
    # *REQUIRED* The default PATH settings, for superuser and normal users.
    # (they are minimal, add the rest in the shell startup files)
    ENV_SUPATH PATH=/sbin:/bin:/usr/sbin:/usr/bin
    ENV_PATH PATH=/bin:/usr/bin
    # Terminal permissions
    # TTYGROUP Login tty will be assigned this group ownership.
    # TTYPERM Login tty will be set to this permission.
    # If you have a "write" program which is "setgid" to a special group
    # which owns the terminals, define TTYGROUP to the group number and
    # TTYPERM to 0620. Otherwise leave TTYGROUP commented out and assign
    # TTYPERM to either 622 or 600.
    TTYGROUP tty
    TTYPERM 0600
    # Login configuration initializations:
    # ERASECHAR Terminal ERASE character ('\010' = backspace).
    # KILLCHAR Terminal KILL character ('\025' = CTRL/U).
    # UMASK Default "umask" value.
    # The ERASECHAR and KILLCHAR are used only on System V machines.
    # The ULIMIT is used only if the system supports it.
    # (now it works with setrlimit too; ulimit is in 512-byte units)
    # Prefix these values with "0" to get octal, "0x" to get hexadecimal.
    ERASECHAR 0177
    KILLCHAR 025
    UMASK 077
    # Password aging controls:
    # PASS_MAX_DAYS Maximum number of days a password may be used.
    # PASS_MIN_DAYS Minimum number of days allowed between password changes.
    # PASS_WARN_AGE Number of days warning given before a password expires.
    PASS_MAX_DAYS 99999
    PASS_MIN_DAYS 0
    PASS_WARN_AGE 7
    # Min/max values for automatic uid selection in useradd
    UID_MIN 1000
    UID_MAX 60000
    # System accounts
    SYS_UID_MIN 500
    SYS_UID_MAX 999
    # Min/max values for automatic gid selection in groupadd
    GID_MIN 1000
    GID_MAX 60000
    # System accounts
    SYS_GID_MIN 500
    SYS_GID_MAX 999
    # Max number of login retries if password is bad
    LOGIN_RETRIES 5
    # Max time in seconds for login
    LOGIN_TIMEOUT 60
    # Which fields may be changed by regular users using chfn - use
    # any combination of letters "frwh" (full name, room number, work
    # phone, home phone). If not defined, no changes are allowed.
    # For backward compatibility, "yes" = "rwh" and "no" = "frwh".
    CHFN_RESTRICT rwh
    # List of groups to add to the user's supplementary group set
    # when logging in on the console (as determined by the CONSOLE
    # setting). Default is none.
    # Use with caution - it is possible for users to gain permanent
    # access to these groups, even when not logged in on the console.
    # How to do it is left as an exercise for the reader...
    #CONSOLE_GROUPS floppy:audio:cdrom
    # Should login be allowed if we can't cd to the home directory?
    # Default in no.
    DEFAULT_HOME yes
    # If defined, this command is run when removing a user.
    # It should remove any at/cron/print jobs etc. owned by
    # the user to be removed (passed as the first argument).
    #USERDEL_CMD /usr/sbin/userdel_local
    # Enable setting of the umask group bits to be the same as owner bits
    # (examples: 022 -> 002, 077 -> 007) for non-root users, if the uid is
    # the same as gid, and username is the same as the primary group name.
    # This also enables userdel to remove user groups if no members exist.
    USERGROUPS_ENAB yes
    Please help.
    Last edited by nbtrap (2012-07-14 21:59:46)

    orbisvicis wrote:see "pam_mail.so" in /etc/pam.d/* and "man pam_mail". You most likely need the nopen argument.
    Thank you. I fixed it by changing a line in /etc/pam.d/system-login. Specifically, I changed
    session optional pam_mail.so dir=/var/spool/mail standard
    to
    session optional pam_mail.so dir=/var/spool/mail nopen

  • Sun Cluster 3.2/Solaris 10 Excessive ICMP traffic

    Hi all,
    I have inherited a 2 node cluster with a 3510 san which I have upgraded to Cluster 3.2/Solaris 10. Apparently this was happening on Cluster 3.0/Solaris 8 as well.
    The real interfaces on the two nodes seem to be sending excessive pings to the default gateway it is connected to. The configuration of the network adapters are the same - 2 NIC's on each are grouped for multi-home and 2 NIC's configured as private for cluster heartbeats.
    The 2 NIC's that are grouped together on each of the servers are the cards generating the traffic.
    23:27:52.402377 192.168.200.216 > 192.168.200.1: icmp: echo request [ttl 1]
    23:27:52.402392 192.168.200.1 > 192.168.200.216: icmp: echo reply
    23:27:52.588793 192.168.200.217 > 192.168.200.1: icmp: echo request [ttl 1]
    23:27:52.588806 192.168.200.1 > 192.168.200.217: icmp: echo reply
    23:27:52.818690 192.168.200.215 > 192.168.200.1: icmp: echo request [ttl 1]
    23:27:52.818714 192.168.200.1 > 192.168.200.215: icmp: echo reply
    23:27:53.072442 192.168.200.214 > 192.168.200.1: icmp: echo request [ttl 1]
    23:27:53.072479 192.168.200.1 > 192.168.200.214: icmp: echo reply
    Here is the setup to one of the servers:
    lo0: flags=2001000849<UP,LOOPBACK,RUNNING,MULTICAST,IPv4,VIRTUAL> mtu 8232 index 1
    inet 127.0.0.1 netmask ff000000
    ce0: flags=9040843<UP,BROADCAST,RUNNING,MULTICAST,DEPRECATED,IPv4,NOFAILOVER> mtu 1500 index 2
    inet 192.168.200.214 netmask ffffff00 broadcast 192.168.200.255
    groupname prod
    ether 0:3:ba:43:f4:f4
    ce0:1: flags=1000843<UP,BROADCAST,RUNNING,MULTICAST,IPv4> mtu 1500 index 2
    inet 192.168.200.212 netmask ffffff00 broadcast 192.168.200.255
    ce1: flags=1008843<UP,BROADCAST,RUNNING,MULTICAST,PRIVATE,IPv4> mtu 1500 index 5
    inet 172.16.0.129 netmask ffffff80 broadcast 172.16.0.255
    ether 0:3:ba:43:f4:f3
    qfe0: flags=9040843<UP,BROADCAST,RUNNING,MULTICAST,DEPRECATED,IPv4,NOFAILOVER> mtu 1500 index 3
    inet 192.168.200.216 netmask ffffff00 broadcast 192.168.200.255
    groupname prod
    ether 0:3:ba:34:95:4
    qfe1: flags=1008843<UP,BROADCAST,RUNNING,MULTICAST,PRIVATE,IPv4> mtu 1500 index 4
    inet 172.16.1.1 netmask ffffff80 broadcast 172.16.1.127
    ether 0:3:ba:34:95:5
    clprivnet0: flags=1009843<UP,BROADCAST,RUNNING,MULTICAST,MULTI_BCAST,PRIVATE,IPv4> mtu 1500 index 6
    inet 172.16.193.1 netmask ffffff00 broadcast 172.16.193.255
    ether 0:0:0:0:0:1
    Any suggestions on why the excessive traffic?

    I would guess these are the ipmp probes (man in.mpathd).
    You can start in.mpathd in debug mode to find out.
    HTH,
    jono

  • Excess network traffic - what's causing it?

    I recently purchased a Mac Mini Server and today I reinstalled my server software to try to fix some permission problems.
    Anyway, I must have turned something on or off incorrectly because my network traffic suddenly started going through the roof for about six hours until the monthly cap with my ISP was exceeded and they slowed my connection.
    Any ideas what could be causing this excessive traffic?
    I am confident that it wasn't the result of any large downloads etc (18GB in 6 hrs!) and I can't help but feel it was just an incorrect setup somewhere.
    As you can probably tell, I'm all new to this server business so please excuse my naivety.
    A screen shot of my network activity graph is at http://idisk.mac.com/mtilley/Public/temp/Activity.png
    I turned the web service off before taking the screen shot but that was about 9:00 pm.

    That could well be it.
    Just checked the size of the downloads - 17.64 GB.
    Thanks cpragman for your much appreciated help.

Maybe you are looking for

  • VPN Server with two router local network

    I just got a Mac Mini Server 2011 to set up as a home server. One of the main features I want to use is a VPN so I can access my files on my local network when I'm away from home. I live in Japan and I have a Japanese optical connection to the intern

  • HT1203 one itunes account 2 iphones

    How do i can manage 1 itunes account, with 2 iPhones, me and my wife, she doesnt need my contacts, But we dont want to buy twice the apps? any ideas?? TXS!

  • Error while inserting .doc file into CLOB object in oracle

    hello everybody , i am trying to insert .doc file into clob column in oracle database.i am using oracle 8i. But i am getting error saying ORA-01461: can bind a LONG value only for insert into a LONG column i have no clue. i am pasting code here pleas

  • Payment orders when a customer has a credit balance

    Hello, I was able to generate a payment order for a customer.  But when a customer has a credit note attached to it that it effectively renders the total as a credit balance,  I am unable to do so.  When I select on the credit note, it comes up with

  • IOS 7 apps save on cloud

    Ok, on my iPhone 4s with IOS 7 apps (free ones) save on the cloud. When I unninstall the app it has a cloud icon with a down arrow on it in the appstore. How do I get it to go back to normal? Thanks in advance.