Could the traffic explosion be explained by broadcast packages? I could imagine broadcasts floating through the network for a long time. I wouldn't see them when I tcpdump the tinc interface if the packages actually stay within the network and are not handed to the kernel.
Unfortunately, I don't understand enough about the tinc internals to asses if that makes sense at all. I saw that in tinc 1.1 there is a possibility to pcap tinc traffic at the local node. Is that possible in tinc 1.0, too? Cheers, Maximilian
signature.asc
Description: OpenPGP digital signature
_______________________________________________ tinc mailing list tinc@tinc-vpn.org https://www.tinc-vpn.org/cgi-bin/mailman/listinfo/tinc