Hello.
I have received a MAC abuse notification ...where my server is using n°3 mac address that aren't allowed for my account!
I have verified all MAC address configured on the virtual machines and proxmox host are all correct no one of the 3 mentioned MAC address are used in my configuration.
But looking in the proxmox firewall log .. I see DROP incoming connections to one of the tap device...where the destination IP of the dropped connection it's not configured on my server and the mac address correspond to 1 of 3 mentioned in the abuse notification.
200 6 tap200i0-IN 04/Sep/2021:22:11:30 +0200 policy DROP: IN=fwbr200i0 OUT=fwbr200i0 PHYSIN=fwln200i0 PHYSOUT=tap200i0 MAC=e8:06:88:ca:33:ff SRC=REMOTE-IP DST=IP-NOT-OWNED-BY-ME LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=25740 PROTO=TCP SPT=34435 DPT=40001 SEQ=643497095 ACK=0 WINDOW=1024 SYN
Also tcpdump confirm incoming (only incoming..) connections addressed to the 3 MAC for IP's who are not in my ip pool.
I use Hetzner server, could be because I use bridged net instead of routed net?!
What's going on?!
I have received a MAC abuse notification ...where my server is using n°3 mac address that aren't allowed for my account!
I have verified all MAC address configured on the virtual machines and proxmox host are all correct no one of the 3 mentioned MAC address are used in my configuration.
But looking in the proxmox firewall log .. I see DROP incoming connections to one of the tap device...where the destination IP of the dropped connection it's not configured on my server and the mac address correspond to 1 of 3 mentioned in the abuse notification.
200 6 tap200i0-IN 04/Sep/2021:22:11:30 +0200 policy DROP: IN=fwbr200i0 OUT=fwbr200i0 PHYSIN=fwln200i0 PHYSOUT=tap200i0 MAC=e8:06:88:ca:33:ff SRC=REMOTE-IP DST=IP-NOT-OWNED-BY-ME LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=25740 PROTO=TCP SPT=34435 DPT=40001 SEQ=643497095 ACK=0 WINDOW=1024 SYN
Also tcpdump confirm incoming (only incoming..) connections addressed to the 3 MAC for IP's who are not in my ip pool.
I use Hetzner server, could be because I use bridged net instead of routed net?!
What's going on?!
Last edited: