[Openswan Users] cause of dropped packets in interface stats

Patrick Naubert patrickn at xelerance.com
Mon Jun 17 13:35:32 UTC 2013

From: Roel van Meer <roel.vanmeer at bokxing-it.nl>
Subject: cause of dropped packets in interface stats
Date: 12 June, 2013 7:45:48 AM EDT
To: users at lists.openswan.org

Hi list,

We're running a linux server with OpenSwan 2.6.38, using KLIPS and with about 100 tunnels. All is working well.

However, the interface statistics of the ipsec0 interface look like this:

ipsec0    Link encap:Ethernet  HWaddr aa:aa:aa:aa:aa:aa
        inet addr:pu.bli.cip.adr Mask:
        UP RUNNING NOARP  MTU:1500  Metric:1
        RX packets:1536163134 errors:0 dropped:3594958 overruns:0 frame:0
        TX packets:1453236498 errors:0 dropped:2455020 overruns:0 carrier:0
        collisions:0 txqueuelen:10
        RX bytes:220749612688 (205.5 GiB)  TX bytes:345964228696 (322.2 GiB)

The dropped packet counters are quite high, which is something I have no explanation for.
Could someone explain in which cases a packet would be dropped?

For transmitted packets, I know one situation, which is if there is a route via ipsec0 and there is currently no tunnel for it. But how about the recieved packets?

As a related question: could this be indicative of a server overload problem?

Thanks in advance,


