Re: Module crash due to broken count

To: Net Filter <netfilternetfilter@xxxxxxxxx>
Subject: Re: Module crash due to broken count
Cc: lvs-devel@xxxxxxxxxxxxxxx
From: Julian Anastasov <ja@xxxxxx>
Date: Wed, 25 Apr 2018 00:46:35 +0300 (EEST)

On Mon, 23 Apr 2018, Net Filter wrote:

> I was requested by Pablo Neira Ayuso to report the netfilter bugzilla
> ticket here.
> The ticket is replicated below for your convenience.
> Start of ticket content:
> The configuration I use is a NixOS keepalived setup on AWS (which uses
> Xen) configured with per packet round robin routing in a direct
> routing setup, which in turn uses ipvs.
> Symptoms are ksoftirqd using 100% of the CPU resulting in what looks
> like a DoS attack on the machine.
> The module repeatedly crashes when in this mode with a message similar
> to the one below.
> [root@keepalive:~]# uname -a
> Linux keepalive 4.15.17 #1-NixOS SMP Thu Apr 12 10:31:21 UTC 2018
> x86_64 GNU/Linux

        What IPVS rules are used? Persistence? Master/Backup sync?
What kind of traffic and its rate?


Julian Anastasov <ja@xxxxxx>
To unsubscribe from this list: send the line "unsubscribe lvs-devel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at

<Prev in Thread] Current Thread [Next in Thread>