Operating System - HP-UX
1849727 Members
6125 Online
104044 Solutions
New Discussion

Re: syslog: gethostbyaddr: in syslog

 
Shane Russell
Regular Advisor

syslog: gethostbyaddr: in syslog

Hi,

I am getting the following messages in /var/adm/syslog/syslog.log ...

Can anyone explain it?

Dec 2 20:13:20 angel syslog: gethostbyaddr: cwecc1.dublin.esat.ie. != 10.40.2.74
Dec 4 18:18:03 angel syslog: gethostbyaddr: cwecc1.dublin.esat.ie. != 10.40.2.74
Dec 4 18:18:05 angel syslog: gethostbyaddr: cwecc1.dublin.esat.ie. != 10.40.2.74
Dec 5 10:42:30 angel syslog: gethostbyaddr: cwecc1.dublin.esat.ie. != 10.40.2.74
Dec 5 10:42:57 angel syslog: gethostbyaddr: cwecc1.dublin.esat.ie. != 10.40.2.74

regards,
Shane
6 REPLIES 6
Sivakumar TS
Honored Contributor

Re: syslog: gethostbyaddr: in syslog

Dear Shane,

I suspect this is due to some issue with syslog.

Was there ay changes performed in syslog config recently before this problem occoured ? / when did this log started commming ?

With Regards,

Siva.
Nothing is Impossible !
Shane Russell
Regular Advisor

Re: syslog: gethostbyaddr: in syslog

Thanks Siva,

There was no changes to /etc/syslog.conf.
Gerrit_1
Advisor

Re: syslog: gethostbyaddr: in syslog

Hi,

The problem is that you have misconfigured DNS boxes for which the reverse DNS does not match the forward DNS, or people are sending
out a mismatching IP name and address.
These messages are not dangerous, although irritating.


Hope this helps
I have a vision...... a television
Shane Russell
Regular Advisor

Re: syslog: gethostbyaddr: in syslog

Thanks Gerrit,

You are on the right track with DNS issues because the IP address 10.40.2.74 does not belong to cwecc1, rather it belongs to bmecc1.

From our DNS servers here are the relavant entries ...
grep ecc dublin.db
bmecc1 IN A 10.40.2.74
cwecc1 IN A 10.40.2.67

And from the host here is the nslookup output for each server.
root@angel:/root # nslookup cwecc1
Using /etc/hosts on: angel

looking up FILES
Trying DNS
Name: cwecc1.dublin.esat.ie
Address: 10.40.2.67

root@angel:/root # nslookup bmecc1
Using /etc/hosts on: angel

looking up FILES
Trying DNS
Name: bmecc1.dublin.esat.ie
Address: 10.40.2.74


So it is resolving the IP/Name properly.

Do I need to refresh my arp cache?
How do I do this?

Thanks in advance
Shane


Gerrit_1
Advisor

Re: syslog: gethostbyaddr: in syslog

Hi,

Displays all of the current ARP entries
#arp -a

Deletes de entry for hostname specific
#arp -d "hostname"

I have a vision...... a television
Shane Russell
Regular Advisor

Re: syslog: gethostbyaddr: in syslog

Thanks Gerrit,

However, the entry is not in the arp cache

root@angel:/root # arp -an
(10.40.3.40) at 0:30:6e:37:2a:60 ether
(10.40.3.35) at 0:30:6e:37:1a:c7 ether
(10.40.3.1) at 0:0:c:7:ac:6 ether
(10.40.3.67) at 0:30:6e:4b:55:a5 ether
(10.40.3.69) at 0:30:6e:4b:57:e9 ether
(10.40.3.40) at 0:30:6e:37:2a:60 ether
(10.40.3.53) at 0:f:ea:eb:50:5 ether
(10.40.3.53) at 0:f:ea:eb:50:5 ether
(10.40.3.52) at 0:f:ea:3d:53:49 ether
(10.40.3.52) at 0:f:ea:3d:53:49 ether
(10.40.3.2) at 0:d0:d3:35:e4:b4 ether
(10.40.3.2) at 0:d0:d3:35:e4:b4 ether
(10.40.3.12) at 0:2:a5:42:1a:7e ether
(10.40.3.12) at 0:2:a5:42:1a:7e ether
(10.40.3.21) at 0:30:6e:6:f2:9e ether
(10.40.3.21) at 0:30:6e:6:f2:9e ether
10.40.3.24 (10.40.3.24) -- no entry
root@angel:/root #

root@angel:/root # traceroute 10.40.2.67
traceroute: Warning: Multiple interfaces found; using 10.40.3.162 @ lan2
traceroute to 10.40.2.67 (10.40.2.67), 30 hops max, 40 byte packets
1 10.40.3.2 (10.40.3.2) 0.575 ms 0.441 ms 0.421 ms
2 10.40.2.67 (10.40.2.67) 0.360 ms 0.353 ms 0.346 ms


root@angel:/root # netstat -rn
Routing tables
Destination Gateway Flags Refs Interface Pmtu
127.0.0.1 127.0.0.1 UH 0 lo0 4136
10.40.3.24 10.40.3.24 UH 0 lan1 4136
10.40.3.162 10.40.3.162 UH 0 lan2 4136
10.40.3.0 10.40.3.162 U 2 lan2 1500
10.40.3.0 10.40.3.24 U 2 lan1 1500
127.0.0.0 127.0.0.1 U 0 lo0 0
default 10.40.3.1 UG 0 lan2 0


root@angel:/root # ping cwecc1
PING cwecc1.dublin.esat.ie: 64 byte packets
64 bytes from 10.40.2.67: icmp_seq=0. time=0. ms
64 bytes from 10.40.2.67: icmp_seq=1. time=0. ms
64 bytes from 10.40.2.67: icmp_seq=2. time=0. ms

----cwecc1.dublin.esat.ie PING Statistics----
3 packets transmitted, 3 packets received, 0% packet loss
round-trip (ms) min/avg/max = 0/0/0
root@angel:/root #

Shane