XCP-ng
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    XOA shows hundreds of client connections

    Scheduled Pinned Locked Moved Xen Orchestra
    8 Posts 5 Posters 761 Views 1 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      snakeice64
      last edited by

      I was just setting up my new router that shows numbers of client connections and was struck by suddenly having hundreds of client connections on my router as static connections where I should have a dozen or so at this stage. Then I noticed I only had the amount of ip.addresses I should on the router but on one ip.address it shows I had over 200 clients coming in on that ip.address. I couldn't ping the ip.address or get to it any other way. Then I proceeded to look up the mac address which doesn't show as a registered MAC address in any MAC address lookup tool which from experience meant it was an XCP-Ng MAC and this happened to belong to the XOA client.

      I have shutdown the client for now and will use XCP-ng Center.

      My question is why would there be 200+ connections coming in over XOA? That seems like a security issue.

      1 Reply Last reply Reply Quote 0
      • olivierlambertO Offline
        olivierlambert Vates 🪐 Co-Founder CEO
        last edited by

        Ping @julien-f

        I'm not aware about any security issues regarding that. Is your XOA fully up to date?

        S 1 Reply Last reply Reply Quote 0
        • julien-fJ Offline
          julien-f Vates 🪐 Co-Founder XO Team
          last edited by

          Just to make sure I understand, you found hundreds of opened (but inactive) connections from XOA to an XCP-ng host?

          1 Reply Last reply Reply Quote 0
          • S Offline
            snakeice64
            last edited by

            This is what I see when XOA client is up and running it has hundreds of connections"
            77a83777-375e-4274-8ed4-dcf75f458e5d-image.png

            Note the 226 client connections next to the computer icon. This occurs as soon as I boot the XOA vm.

            The A2:EC:7E:F2:66:D7 MAC address is xcp-ng as I've noticed even prior to this.

            I'm speculating that perhaps its due to licensing, updates and connectivity to be able to do these types of activities.

            I'm just curious to know why so many connections?

            Anyone have any idea about these connections?

            1 Reply Last reply Reply Quote 0
            • S Offline
              snakeice64 @olivierlambert
              last edited by

              @olivierlambert I have just made sure I'm updated and the same condition is there with the multiple connections, plus I updated my xcp-ng server master and other pool client.

              1 Reply Last reply Reply Quote 0
              • olivierlambertO Offline
                olivierlambert Vates 🪐 Co-Founder CEO
                last edited by

                This is @julien-f domain of expertise 😉

                1 Reply Last reply Reply Quote 0
                • N Offline
                  nhanlon
                  last edited by

                  tcpdump it? Or check netstat while it's running and see what it is.

                  What is that UI? Who honestly knows what it's counting as a 'connection'. I seriously doubt it's individual flows. More than likely, this is related to websockets (in my opinion).

                  But again... a pcap would help in diagnosing.

                  1 Reply Last reply Reply Quote 0
                  • jcpt928J Offline
                    jcpt928
                    last edited by jcpt928

                    I ran into something VERY similar with XCP-ng and\or XOA a while back - ended up with close to 200 new "clients" showing up on my Meraki gear. They weren't even "connected" long enough to register as IP clients, only MAC clients (ARP, possibly). I didn't think much about it at the time, as both the MAC addresses and hardware information didn't seem to be tied to any actual device by some manufacturer. I may be able to pull those out from my client history...

                    EDIT: Here is a small section of that list:
                    fc439a0c96cb13a0b2b11b3bd80ff3be.png

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post