active agents with interface using IP address
server is 7.0.22
proxies are 7.0.19
agents are 7.0.19
tcpdump shows reverse lookups for the agents. Since we defined all agents to use IP address, we did not expect any dns lookup for the agents by the proxy.
tcpdump also shows very frequent requesting active checks for the agents. (every 5s)
Is this expected behaviour?
The zabbix_proxy.log shows many
cannot send list of active checks to XXXXXXX not monitored
(those hosts are disabled so why bother to send at all)
We started looking into this after we had a misbehaving dns.
connects to the proxy timed out.
The TCP receive buffer constantly showed full.
ss -tuln '( sport = 10051 )'
showed Recv-Q 129 where it normally is 0 or very close to 0.
Could this have a relation with the reverse lookups (I guess they also took too long)?
We especially configured everything using IP address to prevent issues when dns has problems.
tcpdump created with -G600 -W1 port 53 or host hostname
I am willing to share the pcap file but not when it is publicly available. (compressed about 200KB)