Forum Discussion
am_gli_287451
Jul 27, 2018Nimbostratus
tcpdump flooded with failover packets
Hi,
I often have a problem with tcpdump on clustered devices.
If I e.g. start a dump like this:
'tcpdump -ni 0.0:p host 192.168.1.1'
the terminal is flooded with messages like these eve...
crodriguez
Jul 27, 2018Ret. Employee
You are not doing anything wrong with your TCPDUMP; you're just capturing more data than you need to. Those packets you're seeing are the network failover "heartbeat" transmitted between devices in a sync-failover device group. If you would rather not see this traffic, then filter out UDP port 1026 on your TCPDUMP command. Or, better yet, filter for the protocol and ports you do want to see.
- Amresh008Jan 13, 2020Nimbostratus
I get similar response even after limiting the traffic capture to port 1026.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects