LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 09-13-2018, 12:41 AM   #1
imtiazb
LQ Newbie
 
Registered: Sep 2018
Posts: 6

Rep: Reputation: Disabled
Angry (URGENT) Broadcast Issue with Server CentOS6.9


Hi, All

Here is a very painful query that we installed CentOS6.9 from scratch on Customer end for Application of VOIP gateway provided by Sangoma with LAN IP of provate pool 192.168.1.151/24. But after installation, it was discovered that whole LAN having Application Server and other PC becomes choked. When we isolated CentOS machine, network is just fine so we fond a culprit but dont know how to fix it. Trying all basic diagnostics, but failed to resolve the issue. Please help out.
 
Old 09-13-2018, 03:06 AM   #2
Keruskerfuerst
Senior Member
 
Registered: Oct 2005
Location: Horgau, Germany
Distribution: Manjaro KDE, Win 10
Posts: 2,199

Rep: Reputation: 164Reputation: 164
Can you try the more recent version of Centos (version 7.5.1804) ?
Or another distro, that is suited for server purposes ?
 
Old 09-13-2018, 03:34 AM   #3
imtiazb
LQ Newbie
 
Registered: Sep 2018
Posts: 6

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by Keruskerfuerst View Post
Can you try the more recent version of Centos (version 7.5.1804) ?
Or another distro, that is suited for server purposes ?
This is requirement by our Sangoma VoIP gateway to have CentOS distro6.9.
 
Old 09-13-2018, 05:42 AM   #4
Keruskerfuerst
Senior Member
 
Registered: Oct 2005
Location: Horgau, Germany
Distribution: Manjaro KDE, Win 10
Posts: 2,199

Rep: Reputation: 164Reputation: 164
Can you check the log files (/var/log/... and dmesg) ?
 
Old 09-13-2018, 05:47 AM   #5
wpeckham
LQ Guru
 
Registered: Apr 2010
Location: Continental USA
Distribution: Debian, Ubuntu, RedHat, DSL, Puppy, CentOS, Knoppix, Mint-DE, Sparky, VSIDO, tinycore, Q4OS, Manjaro
Posts: 5,714

Rep: Reputation: 2734Reputation: 2734Reputation: 2734Reputation: 2734Reputation: 2734Reputation: 2734Reputation: 2734Reputation: 2734Reputation: 2734Reputation: 2734Reputation: 2734
When I have seen this issue in the past (LONG past, it was in the 1990s) it was a hardware failure in a NIC that broadcast noise on the wire overloading the network at the lowest level. Try a different NIC, just as a test.
 
Old 09-13-2018, 11:55 PM   #6
imtiazb
LQ Newbie
 
Registered: Sep 2018
Posts: 6

Original Poster
Rep: Reputation: Disabled
Try /var/log, dmesg and change NIC. It will take time as machine is in the remote site and access is only intermittent.
 
Old 09-14-2018, 01:35 AM   #7
imtiazb
LQ Newbie
 
Registered: Sep 2018
Posts: 6

Original Poster
Rep: Reputation: Disabled
Here is output of /var/log/secure

It shows some foreign IP trying to attempt the machine and it seems some ports are opened for easy access? [Please sugest how to secure it]

2]: Invalid user admin from 77.72.82.39
Sep 11 08:37:02 cmsivr sshd[17553]: input_userauth_request: invalid user admin
Sep 11 08:37:02 cmsivr sshd[17552]: pam_unix(sshd:auth): check pass; user unknown
Sep 11 08:37:02 cmsivr sshd[17552]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=77.72.82.39
Sep 11 08:37:02 cmsivr sshd[17552]: pam_succeed_if(sshd:auth): error retrieving information about user admin
Sep 11 08:37:04 cmsivr sshd[17552]: Failed password for invalid user admin from 77.72.82.39 port 44776 ssh2
Sep 11 08:37:07 cmsivr sshd[17553]: Connection closed by 77.72.82.39
Sep 11 12:19:11 cmsivr sshd[19456]: Did not receive identification string from 83.209.188.154
Sep 11 12:21:14 cmsivr sshd[20433]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=61.219.179.5 user=root
Sep 11 12:21:16 cmsivr sshd[20433]: Failed password for root from 61.219.179.5 port 48002 ssh2
Sep 11 12:21:19 cmsivr sshd[20483]: Received disconnect from 61.219.179.5: 11:
Sep 11 12:23:06 cmsivr sshd[21634]: Invalid user ubnt from 61.219.179.5
Sep 11 12:23:06 cmsivr sshd[21635]: input_userauth_request: invalid user ubnt
Sep 11 12:23:06 cmsivr sshd[21634]: pam_unix(sshd:auth): check pass; user unknown
Sep 11 12:23:06 cmsivr sshd[21634]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=61.219.179.5
Sep 11 12:23:06 cmsivr sshd[21634]: pam_succeed_if(sshd:auth): error retrieving information about user ubnt
Sep 11 12:23:09 cmsivr sshd[21634]: Failed password for invalid user ubnt from 61.219.179.5 port 48053 ssh2
Sep 11 12:23:09 cmsivr sshd[21635]: Received disconnect from 61.219.179.5: 11:
Sep 11 13:02:07 cmsivr sshd[12294]: Invalid user admin from 77.72.82.39
Sep 11 13:02:07 cmsivr sshd[12295]: input_userauth_request: invalid user admin
Sep 11 13:02:07 cmsivr sshd[12294]: pam_unix(sshd:auth): check pass; user unknown
Sep 11 13:02:07 cmsivr sshd[12294]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=77.72.82.39
Sep 11 13:02:07 cmsivr sshd[12294]: pam_succeed_if(sshd:auth): error retrieving information about user admin
Sep 11 13:02:09 cmsivr sshd[12294]: Failed password for invalid user admin from 77.72.82.39 port 53684 ssh2
Sep 11 13:02:14 cmsivr sshd[12294]: pam_unix(sshd:auth): check pass; user unknown
Sep 11 13:02:14 cmsivr sshd[12294]: pam_succeed_if(sshd:auth): error retrieving information about user admin
Sep 11 13:02:16 cmsivr sshd[12294]: Failed password for invalid user admin from 77.72.82.39 port 53684 ssh2
Sep 11 13:02:18 cmsivr sshd[12294]: pam_unix(sshd:auth): check pass; user unknown
Sep 11 13:02:18 cmsivr sshd[12294]: pam_succeed_if(sshd:auth): error retrieving information about user admin
Sep 11 13:02:20 cmsivr sshd[12294]: Failed password for invalid user admin from 77.72.82.39 port 53684 ssh2
Sep 11 13:02:20 cmsivr sshd[12295]: Connection closed by 77.72.82.39
Sep 11 13:02:20 cmsivr sshd[12294]: PAM 2 more authentication failures; logname= uid=0 euid=0 tty=ssh ruser= rhost=77.72.82.39
Sep 12 16:28:42 cmsivr sshd[2798]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=192.168.1.1 user=root
Sep 12 16:28:44 cmsivr sshd[2798]: Failed password for root from 192.168.1.1 port 58737 ssh2
Sep 12 16:28:50 cmsivr sshd[2798]: Failed password for root from 192.168.1.1 port 58737 ssh2
Sep 12 16:29:00 cmsivr sshd[2798]: Accepted password for root from 192.168.1.1 port 58737 ssh2
Sep 12 16:29:00 cmsivr sshd[2798]: pam_unix(sshd:session): session opened for user root by (uid=0)
Sep 12 17:19:23 cmsivr login: pam_unix(login:session): session opened for user root by LOGIN(uid=0)
Sep 12 17:19:23 cmsivr login: ROOT LOGIN ON tty1
Sep 12 17:22:03 cmsivr sshd[2316]: Invalid user 0 from 5.188.10.182
Sep 12 17:22:03 cmsivr sshd[2317]: input_userauth_request: invalid user 0
Sep 12 17:22:03 cmsivr sshd[2316]: Failed none for invalid user 0 from 5.188.10.182
 
Old 09-14-2018, 02:05 AM   #8
kaushalpatel1982
Member
 
Registered: Aug 2007
Location: INDIA
Distribution: CentOS, RHEL, Fedora, Debian, Ubuntu, LinuxMint, Kali Linux, Raspbian
Posts: 166

Rep: Reputation: 10
1. This machine might expose SSH port to the internet. You should stop ssh access on internet right away.

2. If Server is flooding network then try tcpdump or wireshark to find what kind of traffic it is. Check which service is causing this traffic. You can do this troubleshooting by isolating server. connect laptop on the port and check what is happening in the network.
 
Old 09-14-2018, 04:12 AM   #9
wpeckham
LQ Guru
 
Registered: Apr 2010
Location: Continental USA
Distribution: Debian, Ubuntu, RedHat, DSL, Puppy, CentOS, Knoppix, Mint-DE, Sparky, VSIDO, tinycore, Q4OS, Manjaro
Posts: 5,714

Rep: Reputation: 2734Reputation: 2734Reputation: 2734Reputation: 2734Reputation: 2734Reputation: 2734Reputation: 2734Reputation: 2734Reputation: 2734Reputation: 2734Reputation: 2734
Quote:
Originally Posted by kaushalpatel1982 View Post
1. This machine might expose SSH port to the internet. You should stop ssh access on internet right away.
unless your access is ssh from the internet. Then install and configure fail2ban to dictionary attacks quickly block.

Quote:
2. If Server is flooding network then try tcpdump or wireshark to find what kind of traffic it is. Check which service is causing this traffic. You can do this troubleshooting by isolating server. connect laptop on the port and check what is happening in the network.
Always good advice to detect and decode packet traffic. It ONLY helps if there is real packet traffic and not "noise" flooding the link, AND if you understand or have documentation on packet structures.
 
Old 09-14-2018, 05:29 AM   #10
imtiazb
LQ Newbie
 
Registered: Sep 2018
Posts: 6

Original Poster
Rep: Reputation: Disabled
please expalin little more with examples:
 
Old 09-14-2018, 06:44 AM   #11
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,710

Rep: Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972
Quote:
Originally Posted by imtiazb View Post
please expalin little more with examples:
If you're the administrator, and were hired to perform this implementation, it's odd that you don't know how to perform diagnostics. While I realize the machine is in a remote location, if this is 'urgent', you need to ACT like it's urgent. Either GO THERE, and work the problem until it's fixed, or get someone dedicated on site to do things for you.

If you get someone on site, just have them shut off SSH and see what happens. And as you were told, run network diagnostics and FIND OUT what kind of traffic is causing the problem. You were given the names of the utilities, and suggestions...it's now time for you to actually do something with them.
 
Old 09-14-2018, 12:00 PM   #12
imtiazb
LQ Newbie
 
Registered: Sep 2018
Posts: 6

Original Poster
Rep: Reputation: Disabled
thanjs, will send some network guy to perform online duagnistics as guided.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
urgent help for resizing root partition CentOS6 on EC2 vxwo0owxv Linux - Newbie 4 10-17-2013 01:22 PM
[SOLVED] Need Autofs fix for RHEL6.3|Centos6.3 urgent rahilmaknojia Linux - Newbie 10 09-26-2012 01:12 PM
UDP Broadcast Issue raviskar Linux - Networking 2 02-06-2009 07:48 AM
Odd [URGENT] cPanel/WHM Server Issue RobertNikic Linux - Server 26 07-03-2008 05:04 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 03:21 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration