As I have noted in previous threads, Astaro license counting is rather... trigger happy. Once I understood what it did (any IP in a packet that was allowed through not being routed to the default route would be counted) I thought I could create new rules that wouldsolve the problem (by creating rules for individual machines rather than IP range) but it seems it's still not the case.
After running for three weeks without too much problem, the license list is once again "poluted" with non-existing IPs (these are public IPs that aren't assigned to any phisical or virtual interface in the network). These IPs all have been "visible" for a single second: the "first seen" and "last seen" timestamps are the same.
The worse part is that I now have no clue as to what causes these IPs to be listed: all the ALLOW rules in the packet filter now are machine-specific and thes IPs show up nowhere. There is no DHCP on that network, no possibly external entry point and everything is in a locked server rack in a high-security enclosure: there is no way any machine could have been connected and could have used one of the ghosts IPs.
Another puzzling point is that only a few IPs are listed: I would have thought that if this was the result of a network scan, the whole range would have been added (that's what happen if I enable ICMP through the firewall)
What 's happening ?
This thread was automatically locked due to age.