ICMP Redirect creacting invalid route

From: Doug (drheams_at_yahooo.com)
Date: 07/28/03


Date: Sun, 27 Jul 2003 22:30:54 -0700

Hello,
I have a redhat 9 box running nagios to monitor my wide area network. Nagios
pings all of the remote routers every 5 minutes to ensure connectivity and
sends an email when a node is unreachable. The problem I have is due to a
poorly designed network but it is not currently an option to repair it.
Because of the network design, when a wan link goes down the monitoring
system receives an icmp redirect from its default gateway which points it
towards a new invalid gateway. This icmp redirect causes the linux kernel to
add a new route to its cached routing table, viewable through the route -Cn
command, and retry the ping through the new gateway. This obviously times
out and I receive a text page from nagios. When the wan link comes back up
nagios never knows it because it is using an invalid gateway for the ping.
To further add confusion, tcp traffic such as telnet uses the correct route
and works perfectly but a ping or traceroute clearly use the invalid route
and fail. I am able to clear the cach with the ip route flush cache command
but I am trying to avoid the manual intervention. Is there a way to decrease
the time that these routes are cached when an icmp redirect is received? Or
even to disable the caching altogether? I realize this will create extra
traffic on the lan but it is my best option at the moment.



Relevant Pages

  • Re: ping problem ...
    ... PING 192.168.1.1 56bytes of data. ... ifconfig and route output when ping fails. ... tell us a bit about your network. ... an implicit route through a local interface on the 192.168.x.y ...
    (comp.os.linux.networking)
  • Re: Wireless does not see Internet [was: PSK recovery?]
    ... dunno if it will help but route from this system gives ... can you successfully ping 10.1.1.3 from the working system? ... click on your network should restart. ...
    (Ubuntu)
  • RE: More help needed please
    ... I can now ping through the rh box to my main network. ... If so the use a client machine and set it's route to the f/w ... Both nics are set to come up at ...
    (RedHat)
  • Re: Wireless does not see Internet [was: PSK recovery?]
    ... dunno if it will help but route from this system gives ... can you successfully ping 10.1.1.3 from the working system? ... click on your network should restart. ...
    (Ubuntu)
  • RE: ip masquerading/subnets
    ... from box1, i can ping 192.168.1.5 ... from box1, i can't ping 192.168.2.5 ... if by network mangler, you mean "network manager", no, it's not enabled on ... i've tried various route cmds, but it doesn't appear to be working. ...
    (Fedora)