Open ferric-sol opened 3 months ago
Hey @ferric-sol can you try with latest from main
?
That fixed it, thanks @helius-kurt!
Actually, still happening on one out of two hosts:
Aug 29 03:17:05 host881025 validator-firewall[240432]: {"timestamp":"2024-08-29T03:17:05.583126Z","level":"INFO","fields":{"message":"total_packets: 45.43.11.28 = 6"},"target":"validator_firewall::stats_service"}
Aug 29 03:17:05 host881025 validator-firewall[240432]: {"timestamp":"2024-08-29T03:17:05.583276Z","level":"INFO","fields":{"message":"dropped_packets: 45.43.11.28 = 6"},"target":"validator_firewall::stats_service"}
Aug 29 03:17:15 host881025 validator-firewall[240432]: {"timestamp":"2024-08-29T03:17:15.584338Z","level":"INFO","fields":{"message":"total_packets: 45.43.11.28 = 17"},"target":"validator_firewall::stats_service"}
Aug 29 03:17:15 host881025 validator-firewall[240432]: {"timestamp":"2024-08-29T03:17:15.584510Z","level":"INFO","fields":{"message":"dropped_packets: 45.43.11.28 = 17"},"target":"validator_firewall::stats_service"}
Aug 29 03:17:25 host881025 validator-firewall[240432]: {"timestamp":"2024-08-29T03:17:25.585806Z","level":"INFO","fields":{"message":"total_packets: 45.43.11.28 = 17"},"target":"validator_firewall::stats_service"}
Aug 29 03:17:25 host881025 validator-firewall[240432]: {"timestamp":"2024-08-29T03:17:25.586009Z","level":"INFO","fields":{"message":"dropped_packets: 45.43.11.28 = 17"},"target":"validator_firewall::stats_service"}
^C
root@host881025:~/validator-firewall# systemctl stop validator-firewall
root@host881025:~/validator-firewall# cat /etc/systemd/system/validator-firewall.service
[Unit]
Description=Validator Firewall Service
After=network.target
[Service]
Environment=RUST_LOG=info
ExecStart=/usr/local/sbin/validator-firewall --iface bond0 --static-overrides /etc/validator-firewall/static_overrides.yml
Restart=always
[Install]
WantedBy=multi-user.target
root@host881025:~/validator-firewall# cat /etc/validator-firewall/static_overrides.yml
allow:
- name: "ashburn"
ip: 45.43.11.28
deny:
not happening on the other host:
root@ftrx-0009:~/validator-firewall# sudo journalctl -u validator-firewall.service -f | grep 45.43
Aug 29 03:17:06 ftrx-0009 validator-firewall[2949575]: {"timestamp":"2024-08-29T03:17:06.156746Z","level":"INFO","fields":{"message":"total_packets: 45.43.11.28 = 16092"},"target":"validator_firewall::stats_service"}
Aug 29 03:17:06 ftrx-0009 validator-firewall[2949575]: {"timestamp":"2024-08-29T03:17:06.157226Z","level":"INFO","fields":{"message":"dropped_packets: 45.43.11.28 = 0"},"target":"validator_firewall::stats_service"}
Aug 29 03:17:16 ftrx-0009 validator-firewall[2949575]: {"timestamp":"2024-08-29T03:17:16.158195Z","level":"INFO","fields":{"message":"total_packets: 45.43.11.28 = 16101"},"target":"validator_firewall::stats_service"}
Aug 29 03:17:16 ftrx-0009 validator-firewall[2949575]: {"timestamp":"2024-08-29T03:17:16.158756Z","level":"INFO","fields":{"message":"dropped_packets: 45.43.11.28 = 0"},"target":"validator_firewall::stats_service"}
Aug 29 03:17:26 ftrx-0009 validator-firewall[2949575]: {"timestamp":"2024-08-29T03:17:26.160580Z","level":"INFO","fields":{"message":"total_packets: 45.43.11.28 = 16111"},"target":"validator_firewall::stats_service"}
Aug 29 03:17:26 ftrx-0009 validator-firewall[2949575]: {"timestamp":"2024-08-29T03:17:26.161143Z","level":"INFO","fields":{"message":"dropped_packets: 45.43.11.28 = 0"},"target":"validator_firewall::stats_service"}
Aug 29 03:17:36 ftrx-0009 validator-firewall[2949575]: {"timestamp":"2024-08-29T03:17:36.162761Z","level":"INFO","fields":{"message":"total_packets: 45.43.11.28 = 16120"},"target":"validator_firewall::stats_service"}
Aug 29 03:17:36 ftrx-0009 validator-firewall[2949575]: {"timestamp":"2024-08-29T03:17:36.163213Z","level":"INFO","fields":{"message":"dropped_packets: 45.43.11.28 = 0"},"target":"validator_firewall::stats_service"}
Aug 29 03:17:46 ftrx-0009 validator-firewall[2949575]: {"timestamp":"2024-08-29T03:17:46.164079Z","level":"INFO","fields":{"message":"total_packets: 45.43.11.28 = 16130"},"target":"validator_firewall::stats_service"}
Aug 29 03:17:46 ftrx-0009 validator-firewall[2949575]: {"timestamp":"2024-08-29T03:17:46.164561Z","level":"INFO","fields":{"message":"dropped_packets: 45.43.11.28 = 0"},"target":"validator_firewall::stats_service"}
Aug 29 03:17:56 ftrx-0009 validator-firewall[2949575]: {"timestamp":"2024-08-29T03:17:56.167070Z","level":"INFO","fields":{"message":"total_packets: 45.43.11.28 = 16139"},"target":"validator_firewall::stats_service"}
Aug 29 03:17:56 ftrx-0009 validator-firewall[2949575]: {"timestamp":"2024-08-29T03:17:56.167656Z","level":"INFO","fields":{"message":"dropped_packets: 45.43.11.28 = 0"},"target":"validator_firewall::stats_service"}
Aug 29 03:18:06 ftrx-0009 validator-firewall[2949575]: {"timestamp":"2024-08-29T03:18:06.169534Z","level":"INFO","fields":{"message":"total_packets: 45.43.11.28 = 16149"},"target":"validator_firewall::stats_service"}
Aug 29 03:18:06 ftrx-0009 validator-firewall[2949575]: {"timestamp":"2024-08-29T03:18:06.169971Z","level":"INFO","fields":{"message":"dropped_packets: 45.43.11.28 = 0"},"target":"validator_firewall::stats_service"}
Aug 29 03:18:16 ftrx-0009 validator-firewall[2949575]: {"timestamp":"2024-08-29T03:18:16.171628Z","level":"INFO","fields":{"message":"total_packets: 45.43.11.28 = 16159"},"target":"validator_firewall::stats_service"}
Aug 29 03:18:16 ftrx-0009 validator-firewall[2949575]: {"timestamp":"2024-08-29T03:18:16.172071Z","level":"INFO","fields":{"message":"dropped_packets: 45.43.11.28 = 0"},"target":"validator_firewall::stats_service"}
Aug 29 03:18:26 ftrx-0009 validator-firewall[2949575]: {"timestamp":"2024-08-29T03:18:26.173703Z","level":"INFO","fields":{"message":"total_packets: 45.43.11.28 = 16168"},"target":"validator_firewall::stats_service"}
Aug 29 03:18:26 ftrx-0009 validator-firewall[2949575]: {"timestamp":"2024-08-29T03:18:26.174272Z","level":"INFO","fields":{"message":"dropped_packets: 45.43.11.28 = 0"},"target":"validator_firewall::stats_service"}
^C
root@ftrx-0009:~/validator-firewall# cat /etc/validator-firewall/static_overrides.yml
allow:
- name: "ashburn"
ip: 45.43.11.28
deny:
thoughts, @helius-kurt ?
Same issue here. Whitelist IPs get denied anyway
Hey @helius-kurt , sorry to ping. Just a head's up that we are still having this issue. Thanks!
This may be user error so please tell me to stfu.
My static_overrides.yml is as follows:
(It wouldn't work without the deny section)
But I'm seeing this in the logs:
why is it dropping packets from the allow override host? misconfiguration, or am I just missing something?