From owner-freebsd-questions@freebsd.org Wed Feb 22 23:37:47 2017 Return-Path: Delivered-To: freebsd-questions@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id A1484CEA215 for ; Wed, 22 Feb 2017 23:37:47 +0000 (UTC) (envelope-from bc979@lafn.org) Received: from zoom.lafn.org (zoom.lafn.org [108.92.93.123]) by mx1.freebsd.org (Postfix) with ESMTP id 8C7EF188A for ; Wed, 22 Feb 2017 23:37:47 +0000 (UTC) (envelope-from bc979@lafn.org) Received: from [10.0.1.251] (sermon-archive.info [71.177.216.148]) by zoom.lafn.org (Postfix) with ESMTPSA id 5011334AEBB for ; Wed, 22 Feb 2017 15:37:41 -0800 (PST) From: Doug Hardie Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Mime-Version: 1.0 (Mac OS X Mail 10.2 \(3259\)) Subject: netstat interface output Message-Id: Date: Wed, 22 Feb 2017 15:38:40 -0800 To: "freebsd-questions@freebsd.org Questions" X-Mailer: Apple Mail (2.3259) X-Virus-Scanned: clamav-milter 0.98 at zoom.lafn.org X-Virus-Status: Clean X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 22 Feb 2017 23:37:47 -0000 I am starting to develop a nagios check for errors on interfaces. = However, there are some issues with the entries in netstat that I don't = understand. Each interface has multiple entries: one for each address = and one for the link. It would seem to me that the link counts would be = the sum of the other address entries, but it is not. Often it is way = off. At first I thought it was possibly caused by overflows of the = counters since most systems have been running for months. However, = checking one system that was only up for one day, the ip4 count was = considerably larger than the link count. This is shown in one of the = examples below. The other issue is one system seems to lose addresses. The address = quits responding, although one address remains and does work. That = interface has a DHPC assigned address along with several fixed = addresses. For the first few days, all addresses work fine. Then all = the fixed addresses disappear and no longer work. The netstat output = for this is shown below. The first is approximately 1 day after the = system was booted and all addresses are working. The second is the next = day and only the DHCP assigned address remains. Unfortunately that = system is remote and without the fixed addresses I can't access it to = get to the messages file. Network interface status: Name Mtu Network Address Ipkts Ierrs Idrop = Opkts Oerrs Coll Drop bge0 1500 68:5b:35:ab:96:52 3703649 0 0 = 1911094 0 0 0=20 bge0 - 192.168.1.205 192.168.1.205 0 - - = 0 - - -=20 bge0 - 10.0.1.205/32 10.0.1.205 0 - - = 0 - - -=20 bge0 - 192.168.0.205 192.168.0.205 498 - - = 0 - - -=20 bge0 - 192.168.0.0/2 192.168.0.7 3700267 - - = 1912398 - - -=20 lo0 16384 lo0 0 0 0 = 0 0 0 0=20 lo0 - localhost localhost 0 - - = 0 - - -=20 lo0 - fe80::%lo0/64 fe80::1%lo0 0 - - = 0 - - -=20 lo0 - your-net localhost 0 - - = 0 - - -=20 Local system status: 3:01AM up 1 day, 8:08, 0 users, load averages: 0.18, 0.16, 0.11 Network interface status: Name Mtu Network Address Ipkts Ierrs Idrop = Opkts Oerrs Coll Drop bge0 1500 68:5b:35:ab:96:52 6420868 0 0 = 3313113 0 0 0=20 bge0 - 192.168.0.0/2 192.168.0.7 1809545 - - = 934183 - - -=20 lo0 16384 lo0 0 0 0 = 0 0 0 0=20 lo0 - localhost localhost 0 - - = 0 - - -=20 lo0 - fe80::%lo0/64 fe80::1%lo0 0 - - = 0 - - -=20 lo0 - your-net localhost 0 - - = 0 - - -=20 Local system status: 3:01AM up 2 days, 8:08, 0 users, load averages: 0.04, 0.11, 0.08 Any ideas what could cause this? =E2=80=94 Doug